9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.
AI Analysis
GPU register value contents can be leaked from secure workloads to non-secure world, allowing unauthorized access to sensitive data.
Basic Information
ID
CVE-2025-25176
Source
imaginationtech
Published
Jan 13, 2026 at 16:27
Modified
Jan 14, 2026 at 14:38
Affected Product
Vendor
Imagination Technologies
Product
Graphics DDK
Version
1.15 RTM, 1.17 RTM, 1.18 RTM, 23.2 RTM
Affected Versions
Imagination Technologies Graphics DDK 1.15 RTM
Imagination Technologies Graphics DDK 1.17 RTM
Imagination Technologies Graphics DDK 1.18 RTM
Imagination Technologies Graphics DDK 23.2 RTM
Imagination Technologies Graphics DDK 1.17 RTM
Imagination Technologies Graphics DDK 1.18 RTM
Imagination Technologies Graphics DDK 23.2 RTM
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Imagination Technologies
Product
Graphics DDK
Version
1.15 RTM, 1.17 RTM, 1.18 RTM, 23.2 RTM