Junglewise Threat Intelligence

CVE-2026-0134: Google Pixel Information Disclosure in recovery_ui.cpp PostWipeData

CVE-2026-0134 · Severity: info · CVSS 4.3 · Published 2026-06-16

Vendors: Google.

Executive brief

A logic error in the recovery component of Google Pixel devices could prevent user data from being fully erased during a factory reset. This means that sensitive information might remain on the device even after a user attempts to wipe it, potentially allowing a subsequent possessor of the device to access the previous owner's data. The issue is resolved in the June 2026 security update.

Technical details

A logic error exists within the 'PostWipeData' function of 'recovery_ui.cpp' in the Android recovery image for Pixel devices. This flaw prevents the complete erasure of user data during a factory reset operation, leading to unintended data persistence. A local attacker with physical access to the device after a reset could potentially recover sensitive information from the previous user session. The vulnerability is classified as Information Disclosure (ID) and does not require elevated privileges or user interaction beyond the initial reset process. Google addressed this in the June 2026 Pixel Update Bulletin (Bug ID A-438759342).

Affected products

  • Google Pixel Prior to June 2026 update

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References