Junglewise Threat Intelligence

CVE-2026-0150: Google EdgeTPU firmware integer overflow in ExecuteGraph

CVE-2026-0150 · Severity: info · CVSS 7.8 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in the firmware of Google's EdgeTPU, a specialized hardware chip used for accelerating machine learning tasks on Pixel devices. An attacker with high-level system access could exploit this flaw to gain even deeper control over the device, potentially reaching root-level privileges. This could allow for unauthorized access to sensitive data or the ability to modify critical system operations.

Technical details

An integer overflow vulnerability exists within the ExecuteGraph command handler of the Google EdgeTPU firmware. This flaw can be triggered to cause an out-of-bounds write. Exploitation requires local access with root-level privileges and can lead to a local escalation of privilege (EoP). No user interaction is required for successful exploitation. The issue is addressed in the June 2026 Pixel security update (patch level 2026-06-05).

Affected products

  • Google EdgeTPU Firmware Versions prior to June 2026 update

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-05: patched: Security patch level date

References