Junglewise Threat Intelligence

CVE-2026-0192: Google Pixel Bootloader privilege escalation due to missing permission check

CVE-2026-0192 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

Google Pixel devices contain a bootloader vulnerability that allows local attackers with system-level access to escalate their privileges further due to insufficient permission validation. This could allow an attacker who has already compromised the device at the system level to gain complete control over the bootloader, the lowest-level firmware component responsible for device startup and security enforcement.

Technical details

The vulnerability is a privilege escalation (EoP) flaw in the Bootloader component caused by a missing permission check. The attack vector is local, and the threat actor must already have system execution privileges to exploit it; no user interaction is required. The vulnerability was patched in Google Pixel devices with the 2026-09-05 security patch level or later, available since September 15, 2026. This is tracked as CVE-2026-0192 in the official Pixel Update Bulletin.

Affected products

  • Google Pixel Bootloader Prior to 2026-09-05 security patch

Timeline

  • 2026-09-15: published: Published in Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue

References

Related threats