Executive brief
Google Pixel devices contain a use-after-free vulnerability in kernel code due to improper locking mechanisms. An attacker with local access to the device can exploit this flaw to escalate privileges and gain elevated access without needing to execute code with special permissions. This could allow attackers to compromise sensitive device functions and access restricted data.
Technical details
The vulnerability is a use-after-free condition caused by improper synchronization/locking in kernel code affecting Google Pixel devices. The flaw exists in the Google eXperience Processor (GXP) kernel component and can be triggered via local attack vector without requiring additional execution privileges. Exploitation does not require user interaction. An attacker with local access can use this flaw to escalate privileges and gain arbitrary kernel-level code execution. The issue is addressed in the September 2026 Pixel security update (patch level 2026-09-05 or later).
Affected products
- Google Pixel Prior to 2026-09-05 patch level
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched: Patch level 2026-09-05 or later for Pixel devices