Junglewise Threat Intelligence

CVE-2026-56879: Google Pixel Bootloader memory corruption via confused deputy

CVE-2026-56879 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

A memory corruption vulnerability in the Google Pixel bootloader could allow a local attacker with system execution privileges to escalate their access further. The bootloader is the low-level firmware that runs before the main operating system and controls critical device security boundaries. An exploit could potentially bypass security protections and gain elevated control over the device.

Technical details

The vulnerability is a confused deputy flaw in the gmc_mb_msg_handler function of gmc_mba.c, leading to memory corruption. The vulnerability resides in the Bootloader component of Pixel devices and requires System execution privileges to exploit. No user interaction is needed for exploitation. An attacker with system-level access could corrupt memory to achieve local privilege escalation. Patches are available via the 2026-09-05 security patch level for all supported Pixel devices.

Affected products

  • Google Pixel Pre-2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Pixel Update Bulletin issued with patch level 2026-09-05

References

Related threats