Executive brief
A security vulnerability exists in the PowerVR graphics component used in Google Pixel devices. This flaw allows a malicious application installed on the device to gain elevated system privileges without any user interaction. Such an exploit could allow an attacker to bypass security boundaries, potentially leading to unauthorized access to sensitive data or full control over the device's operating system.
Technical details
A logic error exists within the 'OSMMapPMRGeneric' function in 'pmr_os.c', a component of the PowerVR GPU driver. The vulnerability allows an attacker to leverage specific system calls to maliciously expand a Virtual Memory Area (VMA) out of its intended bounds. This out-of-bounds memory manipulation can be exploited by a local attacker to achieve Elevation of Privilege (EoP). The exploit requires no additional execution privileges or user interaction. Google addressed this in the June 2026 Pixel Update Bulletin with a security patch level of 2026-06-05.
Affected products
- Google Pixel Security patch level before 2026-06-05
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-05: patched