Executive brief
The Pixel's video processing unit (VPU) contains a logic error in HEVC video decoding that allows out-of-bounds memory writes. An attacker can exploit this by sending a specially crafted video stream to achieve remote code execution without user interaction or special privileges, potentially compromising the device and accessing sensitive data.
Technical details
A logic error in the s_decode_vui_param function of fw_hevc_dec_header.c in Google Pixel's video processing unit firmware allows an out-of-bounds write vulnerability. The vulnerability exists in the HEVC video decoder component and can be triggered remotely by sending a malicious HEVC-encoded video stream. No authentication, user interaction, or special execution privileges are required for exploitation. An attacker can achieve remote code execution (RCE) on the VPU, potentially compromising device security and data. Patches are available in the 2026-09-05 security patch level and later.
Affected products
- Google Pixel prior to 2026-09-05 security patch level
Timeline
- 2026-09-15: disclosed: Published in Pixel Update Bulletin—September 2026
- 2026-09-05: patched: Fixed in 2026-09-05 security patch level