Executive brief
A security vulnerability exists in the EdgeTPU kernel driver used in Google Pixel devices. The EdgeTPU is a specialized hardware component that accelerates machine learning tasks. An attacker with high-level system privileges could exploit this flaw to further escalate their authority or gain deeper control over the device's operating system, potentially leading to a total compromise of the device's security.
Technical details
A use-after-free vulnerability exists in the EdgeTPU kernel driver, specifically within the 'edgetpu_sync_fence_group_shutdown()' function in 'edgetpu-dmabuf.c'. The flaw is triggered during the shutdown process of sync fence groups, where memory may be accessed after it has been deallocated. A local attacker with System execution privileges can exploit this to achieve further elevation of privilege. No user interaction is required for exploitation. The issue is addressed in the June 2026 Pixel Security Bulletin with patch levels 2026-06-05 or later.
Affected products
- Google Pixel Prior to 2026-06-05 patch level
Timeline
- 2026-06-16: disclosed: Vulnerability disclosed in Google Pixel Update Bulletin
- 2026-06-05: patched: Security patch level date for fix availability