Junglewise Threat Intelligence

CVE-2026-55332: Google Pixel Bootloader out-of-bounds write privilege escalation

CVE-2026-55332 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

Google Pixel devices contain a memory safety vulnerability in the bootloader that allows local attackers to elevate privileges to system level through improper input validation. An attacker with local access to an affected device can trigger an out-of-bounds memory write to gain complete control over the system without requiring user interaction.

Technical details

An out-of-bounds write vulnerability exists in multiple locations within the Google Pixel bootloader due to improper input validation. The bootloader is responsible for initializing the device and verifying the firmware before the operating system loads, making it a critical component. Attack requires local system access; no network vector is available. Successful exploitation allows an attacker with System-level execution privileges to write arbitrary data beyond buffer boundaries, leading to code execution and privilege escalation. Google released patches in the September 2026 security update (patch level 2026-09-05 and later).

Affected products

  • Google Pixel Pre-September 2026 patch level

Timeline

  • 2026-09-15: disclosed: Published in Google Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Patch level 2026-09-05 or later addresses this issue

References

Related threats