Executive brief
Google Pixel devices contain a use-after-free vulnerability in the kernel caused by a race condition. An attacker with local system-level access could exploit this to escalate privileges and execute arbitrary code with kernel privileges, potentially compromising the entire device and any data stored on it.
Technical details
The vulnerability is a use-after-free condition triggered by a race condition in multiple kernel locations. It requires System execution privileges as a precondition and can be exploited locally without user interaction. The race condition allows an attacker to access memory that has already been freed, leading to arbitrary code execution at the kernel level. Patches are available in the Pixel Update Bulletin dated September 15, 2026, with the 2026-09-05 security patch level addressing this issue.
Affected products
- Google Pixel prior to 2026-09-05 security patch
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched