Junglewise Threat Intelligence

CVE-2026-55359: Google Pixel GPCA permission bypass

CVE-2026-55359 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Google Pixel devices contain a logic error in the GPCA (Google Pixel Companion App) component that allows a local attacker with user-level access to bypass permission checks and escalate to higher privileges without user interaction. This could allow malicious software already running on a device to gain unauthorized access to sensitive system functions and data.

Technical details

The vulnerability is a permission bypass due to a logic error in the GPCA component of Google Pixel devices. The flaw allows local escalation of privilege when an attacker has user execution privileges. No user interaction is required for exploitation. The attack vector is local, and the vulnerability has been patched in the September 2026 security update (patch level 2026-09-05 or later).

Affected products

  • Google Pixel prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats