Junglewise Threat Intelligence

CVE-2026-0133: Google Android privilege escalation in ARM SMMU driver

CVE-2026-0133 · Severity: info · CVSS 7.8 · Published 2026-06-16

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability exists in the memory management component of Google Pixel devices. This flaw allows a malicious application already on the device to gain elevated system privileges without any user interaction. This could lead to a total compromise of the device's security, allowing unauthorized access to sensitive data or system functions.

Technical details

A privilege escalation vulnerability exists in the 'smmu_attach_dev' function within 'arm-smmu-v3.c' of the Android kernel. The root cause is a missing permission check that allows an attacker to sign malicious Android Runtime (ART) bootclass artifacts. This exploit can be triggered locally without requiring additional execution privileges or user interaction. Successful exploitation allows a local attacker to achieve Elevation of Privilege (EoP). Google has addressed this in the June 2026 Pixel Update Bulletin; devices with a security patch level of 2026-06-05 or later are protected.

Affected products

  • Google Android Pixel devices with security patch levels before 2026-06-05

Timeline

  • 2026-06-16: disclosed: NVD and Google Pixel Update Bulletin published
  • 2026-06-05: patched: Security patch level date for fix

References

Related threats