Executive brief
A vulnerability in the Google Pixel bootloader could allow a local attacker to access sensitive information that should be protected. The bootloader is the critical software that starts the device and ensures its security; an exploit here could compromise the privacy of device data. This issue is resolved in the June 2026 security update for Pixel devices.
Technical details
An out-of-bounds read vulnerability exists in the 'iavb_parse_key_data' function within 'avb_rsa.c' of the Google Pixel Bootloader. The flaw is caused by improper input validation during the parsing of RSA key data. A local attacker can exploit this to read sensitive memory contents without requiring additional execution privileges or user interaction. This vulnerability is tracked by Google as bug A-485031572 and was addressed in the June 2026 Pixel Update Bulletin.
Affected products
- Google Pixel Bootloader Devices updated before June 2026 patch level
Timeline
- 2026-06-16: disclosed: Published in the June 2026 Pixel Update Bulletin
- 2026-06-05: patched: Security patch level date for fix