Executive brief
Google Pixel devices contain a bootloader vulnerability that allows local attackers with system-level access to escalate their privileges further due to insufficient permission validation. This could allow an attacker who has already compromised the device at the system level to gain complete control over the bootloader, the lowest-level firmware component responsible for device startup and security enforcement.
Technical details
The vulnerability is a privilege escalation (EoP) flaw in the Bootloader component caused by a missing permission check. The attack vector is local, and the threat actor must already have system execution privileges to exploit it; no user interaction is required. The vulnerability was patched in Google Pixel devices with the 2026-09-05 security patch level or later, available since September 15, 2026. This is tracked as CVE-2026-0192 in the official Pixel Update Bulletin.
Affected products
- Google Pixel Bootloader Prior to 2026-09-05 security patch
Timeline
- 2026-09-15: published: Published in Pixel Update Bulletin—September 2026
- 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue