Junglewise Threat Intelligence

CVE-2026-55351: Google Pixel VPU integer overflow leading to privilege escalation

CVE-2026-55351 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

The VPU (Video Processing Unit) in Google Pixel devices contains an integer overflow vulnerability that can be exploited to write data outside allocated memory bounds. An attacker with local access to an affected device can use this flaw to escalate their privileges without needing special permissions or user interaction, potentially gaining full system control.

Technical details

The vulnerability is an integer overflow in the VPU (Video Processing Unit) component that results in an out-of-bounds write condition. The root cause involves improper integer bounds checking in the VPU processing logic, which can be triggered by a local attacker without requiring additional execution privileges or user interaction. The out-of-bounds write enables privilege escalation to a higher system privilege level. Google released patches as part of the September 2026 security update (patch level 2026-09-05 or later) for all supported Pixel devices.

Affected products

  • Google Pixel Android devices prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats