Junglewise Threat Intelligence

CVE-2026-56892: Google Pixel Secure World information disclosure in ReadDataElement

CVE-2026-56892 · Severity: medium · CVSS 6.2 · Published 2026-09-15

Executive brief

Google Pixel devices contain an information disclosure vulnerability in the Secure World component (a trusted execution environment managing sensitive operations). An attacker with local access to the device can exploit an incorrect bounds check in the ReadDataElement function to leak confidential information without requiring special privileges or user interaction.

Technical details

The vulnerability exists in ReadDataElement of common.c in the Secure World component, a trusted execution environment (TEE) that handles cryptographic keys, biometric data, and other sensitive operations. An incorrect bounds check allows memory reads outside intended boundaries, resulting in information disclosure. The vulnerability requires local access but does not need elevation of privileges or user interaction for exploitation. An attacker with shell access to the device can trigger the bounds check bypass to read sensitive data from memory. A patch is available as part of the 2026-09-05 security patch level for all supported Google Pixel devices.

Affected products

  • Google Pixel firmware before 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats