Junglewise Threat Intelligence

CVE-2026-0142: Google Pixel Bootloader out of bounds read in iavb_parse_key_data

CVE-2026-0142 · Severity: info · CVSS 5.5 · Published 2026-06-16

Technologies: Google Pixel Bootloader. Vendors: Google.

Executive brief

A vulnerability in the Google Pixel bootloader could allow a local attacker to access sensitive information that should be protected. The bootloader is the critical software that starts the device and ensures its security; an exploit here could compromise the privacy of device data. This issue is resolved in the June 2026 security update for Pixel devices.

Technical details

An out-of-bounds read vulnerability exists in the 'iavb_parse_key_data' function within 'avb_rsa.c' of the Google Pixel Bootloader. The flaw is caused by improper input validation during the parsing of RSA key data. A local attacker can exploit this to read sensitive memory contents without requiring additional execution privileges or user interaction. This vulnerability is tracked by Google as bug A-485031572 and was addressed in the June 2026 Pixel Update Bulletin.

Affected products

  • Google Pixel Bootloader Devices updated before June 2026 patch level

Timeline

  • 2026-06-16: disclosed: Published in the June 2026 Pixel Update Bulletin
  • 2026-06-05: patched: Security patch level date for fix

References

Related threats