Junglewise Threat Intelligence

CVE-2026-0183: Google Pixel CPM information disclosure via confused deputy

CVE-2026-0183 · Severity: medium · CVSS 4.4 · Published 2026-09-15

Executive brief

Google Pixel devices contain a vulnerability in the CPM (Credential and Permission Manager) component that allows local attackers with system-level execution privileges to read sensitive information through a confused deputy attack. An attacker who gains system-level access to a Pixel device could exploit this flaw to disclose confidential data without requiring user interaction.

Technical details

CVE-2026-0183 is an information disclosure vulnerability in the CPM component of Google Pixel firmware, stemming from a confused deputy flaw. The vulnerability requires local access with system execution privileges to exploit but does not require user interaction. An attacker with system-level permissions can abuse the improper privilege handling in CPM to read data that should be restricted. This issue affects the Pixel security subsystem and is addressed in the 2026-09-05 security patch level published in September 2026.

Affected products

  • Google Pixel Firmware prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed: Published in Pixel Update Bulletin September 2026
  • 2026-09-05: patched: Addressed in 2026-09-05 security patch level

References

Related threats