Executive brief
A flaw in Google's Goodix fingerprint trusted application allows local attackers to write data beyond allocated memory boundaries due to improper input validation in the gf_ta_test_set_config function. An attacker with local access can exploit this vulnerability to escalate their privileges without requiring additional permissions or user interaction, compromising the security of the device.
Technical details
The vulnerability is an out-of-bounds write in the gf_ta_test_set_config function within gf_ta_test.c of the Goodix Fingerprint Trusted Application. The root cause is improper input validation on configuration parameters passed to this function. The attack vector is local; no special execution privileges or user interaction are required for exploitation. A successful exploit allows privilege escalation within the trusted execution environment. Patches were made available as part of the September 2026 Pixel security update (patch level 2026-09-05).
Affected products
- Google Goodix Fingerprint TA
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched: Included in Pixel September 2026 security update (patch level 2026-09-05)