Executive brief
A memory corruption vulnerability exists in the Trusted Execution Environment (TEE), a security processor that handles sensitive operations like fingerprint authentication and encryption key management on Pixel devices. An attacker with system-level access could exploit this flaw to gain even higher privileges and potentially compromise the entire device, including sensitive data and security mechanisms.
Technical details
The vulnerability is a memory corruption issue caused by improper input validation in the Trusted Execution Environment. It allows local privilege escalation to system execution privileges without requiring user interaction. An attacker must already have local system access to exploit this vulnerability. The flaw enables escalation from an unprivileged context to the TEE's execution level, which could allow unauthorized access to cryptographic keys, biometric data, or other security-critical operations. Google addressed this vulnerability in the 2026-09-05 security patch level for Pixel devices.
Affected products
- Google Pixel 2026-09-05 patch level and later
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched