Junglewise Threat Intelligence

CVE-2026-56960: Google Pixel use-after-free in kernel

CVE-2026-56960 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

A use-after-free vulnerability in Google Pixel device firmware allows a local attacker to escalate privileges and gain complete control of the device without requiring user interaction or special permissions. This vulnerability could enable theft of sensitive data, installation of malware, or unauthorized access to corporate or personal information stored on the device.

Technical details

A use-after-free vulnerability due to a logic error exists in multiple locations within the Pixel kernel and firmware components. The vulnerability is reachable via a network vector and requires no additional execution privileges or user interaction for exploitation. An attacker can exploit this to achieve remote escalation of privilege (EoP) and potentially remote code execution (RCE) depending on the affected subcomponent. Patches were made available as part of the 2026-09-05 security patch level for all supported Pixel devices.

Affected products

  • Google Pixel 2026-09-05 patch level and earlier

Timeline

  • 2026-09-15: disclosed: Published in Google Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Patch level 2026-09-05 addresses this issue

References

Related threats