Executive brief
A security vulnerability exists in the video processing component of Google Pixel devices. A malicious application installed on the device could exploit this flaw to gain elevated system privileges. This could allow an attacker to bypass security restrictions and access sensitive data or control core device functions without any user interaction.
Technical details
A use-after-free (UAF) vulnerability exists in the Pixel Video Processing Unit (VPU) kernel driver, specifically within multiple functions of the 'vpu_ioctl.c' component. The flaw is rooted in a race condition during IOCTL (Input/Output Control) operations, where memory may be accessed after it has been freed. A local attacker with no special privileges can exploit this race condition to achieve arbitrary code execution in the context of the kernel, leading to local privilege escalation (EoP). The vulnerability does not require user interaction. Google addressed this issue in the June 2026 Pixel Update Bulletin with security patch level 2026-06-05.
Affected products
- Google Pixel Devices Security patch levels before 2026-06-05
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-05: patched