Executive brief
A vulnerability in the Camera application on Google Pixel devices allows for unauthorized access to photos. This flaw stems from a missing permission check, which could enable a local attacker or malicious application to view private images without the user's knowledge or consent. This issue poses a risk to user privacy and data confidentiality.
Technical details
A vulnerability in the Google Pixel Camera component (tracked as bug A-420435325) is caused by a missing permission check. This flaw allows a local attacker or a malicious application installed on the device to bypass standard access controls and retrieve photos without requiring additional execution privileges or user interaction. The vulnerability is classified as Information Disclosure (ID) and was addressed in the June 2026 Pixel Security Bulletin. Users are advised to update their devices to the security patch level of 2026-06-05 or later.
Affected products
- Google Pixel Update levels prior to June 5, 2026
Timeline
- 2026-06-16: disclosed: NVD publication date
- 2026-06-16: advisory: Google Pixel Update Bulletin published
- 2026-06-05: patched: Security patch level date for fix