GUARDED 2 min read 25 Aug 2026

Multiple vulnerabilities in Nvidia GPU Display Treiber Leads Today's Security Review

Threat Level: Guarded Tags: cve-2025-23280, cve-2025-23282, cve-2025-23300, cve-2025-23309, cve-2025-23330, cve-2025-23332, cve-2025-23345, cve-2025-23347, cve-2025-23352, cwe-416

Key findings
01
Multiple vulnerabilities in Nvidia GPU Display Treiber
HIGH
An attacker can exploit multiple vulnerabilities in Nvidia GPU Display Treiber to execute arbitrary code, cause a denial of service, escalate privileges, manipulate data or disclose information.
02
Multiple vulnerabilities in Nvidia Treiber
HIGH
A local attacker can exploit multiple vulnerabilities in Nvidia Treibern to execute arbitrary code, escalate privileges or disclose or manipulate information.
03
Multiple vulnerabilities in Nvidia Treiber
HIGH
An attacker can exploit multiple vulnerabilities in Nvidia Treiber to execute arbitrary code, cause a denial of service, disclose information, escalate privileges or manipulate data.
04
Still active: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability
MEDIUM
First reported 2026-08-14; ongoing coverage. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Executive assessment

Today's brief leads with Multiple vulnerabilities in Nvidia GPU Display Treiber. All 4 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Multiple vulnerabilities in Nvidia GPU Display Treiber

What changed: An attacker can exploit multiple vulnerabilities in Nvidia GPU Display Treiber to execute arbitrary code, cause a denial of service, escalate privileges, manipulate data or disclose information. CVE coverage: CVE-2025-23280, CVE-2025-23282, CVE-2025-23300, CVE-2025-23309, CVE-2025-23330, CVE-2025-23332, CVE-2025-23345, CVE-2025-23347, CVE-2025-23352.

Technical evidence: CVE-2025-23280; CVSS v3.1 7; weakness ['CWE-416']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-23280 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2247>)

Finding 02 — Multiple vulnerabilities in Nvidia Treiber

What changed: A local attacker can exploit multiple vulnerabilities in Nvidia Treibern to execute arbitrary code, escalate privileges or disclose or manipulate information. CVE coverage: CVE-2022-21813, CVE-2022-21814, CVE-2022-21815, CVE-2022-21816, CVE-2025-23276, CVE-2025-23277, CVE-2025-23278, CVE-2025-23279, CVE-2025-23281, CVE-2025-23283, CVE-2025-23284, CVE-2025-23285, CVE-2025-23286, CVE-2025-23287, CVE-2025-23288, CVE-2025-23290.

Technical evidence: CVE-2025-23276; CVSS v3.1 7.8; weakness ['CWE-552']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-23276 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2532>)

Finding 03 — Multiple vulnerabilities in Nvidia Treiber

What changed: An attacker can exploit multiple vulnerabilities in Nvidia Treiber to execute arbitrary code, cause a denial of service, disclose information, escalate privileges or manipulate data. CVE coverage: CVE-2025-23244, CVE-2025-23245, CVE-2025-23246, CVE-2025-33217, CVE-2025-33218, CVE-2025-33219, CVE-2025-33220, CVE-2025-33237.

Technical evidence: CVE-2025-23244; CVSS v3.1 7.8; weakness ['CWE-863']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-23244 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0882>)

Finding 04 — Still active: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

Coverage status: First reported 2026-08-14; ongoing coverage.

What changed: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Technical evidence: CVE-2026-64715; CVSS v3.1 6.5; weakness ['CWE-416']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-64715 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-610/>)

cve-2022-21813cve-2025-23244cve-2025-23280cve-2025-23282cve-2025-23300cve-2025-23309cve-2025-23330cve-2025-23332cve-2025-23345cve-2025-23347

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.