Junglewise Threat Intelligence

CVE-2026-0171: Google Pixel BigWave out-of-bounds write privilege escalation

CVE-2026-0171 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

BigWave is a firmware component used in Google Pixel devices to manage digital signal processing and hardware control. An out-of-bounds write vulnerability in BigWave could allow a local attacker to gain elevated privileges on the device, potentially compromising the security and integrity of all data and services running on it.

Technical details

This is an out-of-bounds write vulnerability caused by a logic error in BigWave firmware component. The vulnerability is classified as a privilege escalation (EoP) and requires no additional execution privileges or user interaction to exploit. The vulnerability can be triggered via local network or adjacent access to trigger the code path containing the buffer overflow. A successful exploit allows an attacker to execute arbitrary code with elevated privileges within the BigWave subsystem. The vulnerability was patched in the September 2026 Pixel security update (patch level 2026-09-05 or later).

Affected products

  • Google Pixel Prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats