Junglewise Threat Intelligence

CVE-2026-0197: Google Pixel VPU information disclosure due to logic error

CVE-2026-0197 · Severity: medium · CVSS 4.4 · Published 2026-09-15

Executive brief

The VPU (Video Processing Unit) is a specialized processor in Google Pixel devices that handles video encoding and decoding. A logic error in the VPU firmware allows an attacker with system-level privileges to read sensitive information from the device's memory, potentially exposing personal data, credentials, or other confidential content without user interaction.

Technical details

The vulnerability is an information disclosure flaw in the VPU firmware caused by a logic error in the code. It requires System execution privileges to exploit and does not require user interaction. The attack vector is local access to the device at the system level. An attacker with these privileges can leverage the logic error to bypass access controls or read protected memory regions in the VPU, exposing sensitive information. The issue was patched in the 2026-09-05 Android security patch level for Pixel devices.

Affected products

  • Google Pixel Prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats