Junglewise Threat Intelligence

CVE-2026-56945: Google Pixel VPU out-of-bounds write in confused deputy

CVE-2026-56945 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Google Pixel devices contain a VPU (Video Processing Unit) firmware component with an out-of-bounds memory write vulnerability caused by a confused deputy flaw. An attacker with local access to the device can exploit this to escalate privileges without requiring additional permissions or user interaction, potentially gaining full device control.

Technical details

The vulnerability is an out-of-bounds write in the VPU (Video Processing Unit) component caused by a confused deputy condition—a scenario where one software component mishandles a resource on behalf of another with inadequate access control. The flaw allows local privilege escalation (EoP) with no additional execution privileges required and no user interaction needed. The attack is limited to local vectors only. A fix is available through the September 2026 security patch level (2026-09-05 or later) for all supported Google Pixel devices.

Affected products

  • Google Pixel Android devices prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue

References

Related threats