Junglewise Threat Intelligence

CVE-2026-0199: Google Goodix Fingerprint TA out-of-bounds write

CVE-2026-0199 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

A flaw in Google's Goodix fingerprint trusted application allows local attackers to write data beyond allocated memory boundaries due to improper input validation in the gf_ta_test_set_config function. An attacker with local access can exploit this vulnerability to escalate their privileges without requiring additional permissions or user interaction, compromising the security of the device.

Technical details

The vulnerability is an out-of-bounds write in the gf_ta_test_set_config function within gf_ta_test.c of the Goodix Fingerprint Trusted Application. The root cause is improper input validation on configuration parameters passed to this function. The attack vector is local; no special execution privileges or user interaction are required for exploitation. A successful exploit allows privilege escalation within the trusted execution environment. Patches were made available as part of the September 2026 Pixel security update (patch level 2026-09-05).

Affected products

  • Google Goodix Fingerprint TA

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Included in Pixel September 2026 security update (patch level 2026-09-05)

References

Related threats