Executive brief
A logic error in the Pixel device bootloader's ac_init_one_sswrp function allows a local attacker with system-level access to escalate privileges. An attacker with existing system execution privileges can exploit this vulnerability to gain further elevated access, potentially compromising device security and enabling unauthorized actions.
Technical details
This vulnerability exists in the ac_init_one_sswrp function within init.c of the Google Pixel Bootloader component. The flaw stems from a logic error in the code that fails to properly validate or enforce access controls. The attack vector is local and requires the attacker to already possess System execution privileges; no user interaction is needed for successful exploitation. An attacker can leverage this flaw to escalate privileges beyond their current level. A patch is available via the September 2026 Pixel security update (patch level 2026-09-05 or later).
Affected products
- Google Pixel Bootloader Prior to 2026-09-05 patch level
Timeline
- 2026-09-15: disclosed: Disclosed in Pixel Update Bulletin September 2026
- 2026-09-05: patched: Security patch available at patch level 2026-09-05 or later