Junglewise Threat Intelligence

CVE-2026-0151: Google Pixel PowerVR GPU integer overflow in IntfGraphCreate

CVE-2026-0151 · Severity: info · CVSS 7.8 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in the PowerVR GPU component of Google Pixel devices. This flaw could allow a remote attacker to execute malicious code on a user's device without any interaction from the user. Such an exploit could lead to full device compromise, unauthorized access to personal data, or disruption of services.

Technical details

A vulnerability exists in the 'IntfGraphCreate' function within 'intfgraph.c' of the PowerVR GPU driver used in Google Pixel devices. The flaw is caused by an integer overflow that results in an out-of-bounds (OOB) write memory corruption. An attacker can exploit this to achieve remote code execution (RCE) with no additional privileges or user interaction required. The issue is addressed in the June 2026 Pixel Update Bulletin, specifically for devices with a security patch level of 2026-06-05 or later.

Affected products

  • Google Pixel Devices with security patch levels before 2026-06-05

Timeline

  • 2026-06-16: disclosed: NVD publication date
  • 2026-06-16: advisory: Google Pixel Update Bulletin published
  • 2026-06-05: patched: Security patch level date addressing the issue

References