Junglewise Threat Intelligence

CVE-2026-55366: Google Pixel IP Multimedia Subsystem authentication bypass

CVE-2026-55366 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

The IP Multimedia Subsystem (IMS) handles voice and messaging services on Google Pixel phones. A logic error in the authentication code allows attackers to bypass security checks and gain elevated privileges on the device without user interaction, potentially enabling unauthorized access to calls, messages, and sensitive device functionality.

Technical details

The vulnerability is an authentication bypass in the IP Multimedia Subsystem due to a logic error in the authentication code. The flaw allows remote attackers to escalate privileges without needing additional execution privileges or user interaction. The vulnerability is remotely exploitable over the network and affects the telephony/IMS stack on Google Pixel devices. Google issued a security patch with the 2026-09-05 patch level to address this issue.

Affected products

  • Google Pixel prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats