Junglewise Threat Intelligence

CVE-2026-56941: Google Pixel Trusted Execution Environment use-after-free in fpc_tee_hal

CVE-2026-56941 · Severity: high · CVSS 8.4 · Published 2026-09-15

Executive brief

A use-after-free vulnerability exists in the fingerprint authentication component of Google Pixel devices' trusted execution environment (TEE). An attacker with local access to the device can exploit this logic error to gain elevated privileges without requiring any additional permissions or user interaction, potentially compromising the security of sensitive operations like biometric authentication and encryption key management.

Technical details

A use-after-free vulnerability exists in multiple functions of fpc_tee_hal.c, a component that manages Goodix fingerprint sensor interaction within the TEE. The vulnerability stems from a logic error that allows freed memory to be accessed. The attack vector is local; an attacker with local code execution can trigger the vulnerability without elevated privileges or user interaction. Exploitation results in local privilege escalation within the TEE. A patch addressing this issue was included in the 2026-09-05 Pixel security update.

Affected products

  • Google Pixel prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats