Junglewise Threat Intelligence

CVE-2026-0153: Google Pixel EdgeTPU out-of-bounds write in msg_to_host_buffer.cc

CVE-2026-0153 · Severity: info · CVSS 8.4 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in the EdgeTPU component of Google Pixel devices, which is responsible for accelerating machine learning tasks. An attacker with local access to the device could exploit this flaw to gain elevated system privileges. This could allow unauthorized access to sensitive data or the ability to modify system settings without user interaction.

Technical details

An out-of-bounds write vulnerability exists in the 'msg_to_host_buffer.cc' component of the Google Pixel EdgeTPU driver. The flaw is caused by an incorrect bounds check during write operations. A local attacker can exploit this to overwrite memory, leading to an escalation of privilege (EoP) from a low-privileged context to a higher one. The vulnerability does not require additional execution privileges or user interaction. It was addressed in the June 2026 Pixel Security Bulletin.

Affected products

  • Google Pixel Prior to June 2026 security patch

Timeline

  • 2026-06-16: advisory: Initial publication of the Pixel Update Bulletin and NVD entry.
  • 2026-06-05: patched: Security patch level date for Pixel devices.

References