Junglewise Threat Intelligence

CVE-2026-55323: Google Pixel Goodix Fingerprint TA heap buffer overflow

CVE-2026-55323 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

A heap buffer overflow vulnerability exists in the Goodix fingerprint authentication component of Google Pixel devices. An attacker with local access can exploit this to bypass security restrictions and gain elevated privileges on the device, potentially compromising sensitive data and device functionality without needing to trick a user or have special device permissions.

Technical details

The vulnerability is a heap buffer overflow in the gf_base_update_finger_base function of gf_base.c in the Goodix Fingerprint Trusted Application (TA). The flaw results in an out-of-bounds write that can be exploited to achieve privilege escalation. The attack vector is local, and no additional execution privileges or user interaction are required for exploitation. The issue was patched as part of the Google Pixel security update with patch level 2026-09-05 or later.

Affected products

  • Google Pixel Pixel devices with security patch level prior to 2026-09-05

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats