Junglewise Threat Intelligence

CVE-2026-56922: Google Pixel CPM permission bypass via confused deputy

CVE-2026-56922 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

CPM (Credential Provider Manager) is a core Android component that manages cryptographic credentials and permissions on Pixel devices. A permission bypass vulnerability allows a local attacker with system privileges to escalate their access without any user interaction, potentially leading to complete device compromise or unauthorized access to sensitive functions.

Technical details

CVE-2026-56922 is a confused deputy vulnerability in Pixel's CPM (Credential Provider Manager) component that permits privilege escalation. The flaw allows an authenticated local attacker with system execution privileges to bypass permission checks and escalate their privileges further. The vulnerability is a logic error in permission validation rather than a network-reachable flaw. No user interaction is required for exploitation. Google addressed this issue in the 2026-09-05 security patch level, with the fix tracked under AOSP change A-510475578.

Affected products

  • Google Pixel Prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed: Published in Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Fix included in 2026-09-05 security patch level

References

Related threats