Junglewise Threat Intelligence

CVE-2026-0143: Google Pixel LWIS use-after-free in lwis_device_external_event_emit

CVE-2026-0143 · Severity: info · CVSS 5.5 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in the LWIS component of Google Pixel devices. This flaw could allow a malicious application already running with high-level system privileges to further corrupt memory and potentially gain even deeper control over the device. While it requires significant existing access to exploit, it could be used by advanced threats to bypass security boundaries and maintain a persistent foothold on the phone.

Technical details

A use-after-free (UAF) vulnerability exists in the 'lwis_device_external_event_emit' function within 'lwis_event.c' of the LWIS (Lightweight Imaging Subsystem) driver. The flaw is triggered when the system attempts to use a memory object after it has been deallocated, leading to memory corruption. Exploitation requires the attacker to already possess 'System' execution privileges on the local device. Successful exploitation allows for local escalation of privilege (EoP) and potentially arbitrary code execution in a higher-privileged context. Google addressed this in the June 2026 Pixel Update Bulletin; devices with a security patch level of 2026-06-05 or later are protected.

Affected products

  • Google Pixel Security patch levels before 2026-06-05

Timeline

  • 2026-06-16: disclosed: Vulnerability details published in the June 2026 Pixel Security Bulletin
  • 2026-06-05: patched: Security patch level date for the fix

References