Executive brief
Google Pixel devices contain a vulnerability in the CPM (Credential and Permission Manager) component that allows local attackers with system-level execution privileges to read sensitive information through a confused deputy attack. An attacker who gains system-level access to a Pixel device could exploit this flaw to disclose confidential data without requiring user interaction.
Technical details
CVE-2026-0183 is an information disclosure vulnerability in the CPM component of Google Pixel firmware, stemming from a confused deputy flaw. The vulnerability requires local access with system execution privileges to exploit but does not require user interaction. An attacker with system-level permissions can abuse the improper privilege handling in CPM to read data that should be restricted. This issue affects the Pixel security subsystem and is addressed in the 2026-09-05 security patch level published in September 2026.
Affected products
- Google Pixel Firmware prior to 2026-09-05 patch level
Timeline
- 2026-09-15: disclosed: Published in Pixel Update Bulletin September 2026
- 2026-09-05: patched: Addressed in 2026-09-05 security patch level