Executive brief
Google Pixel devices contain an out-of-bounds memory write vulnerability in the bootloader firmware due to incorrect bounds checking. An attacker with system-level access can exploit this to escalate privileges and gain complete control of the device. The vulnerability affects all Pixel devices until patched with the September 2026 security update.
Technical details
The vulnerability is a classic out-of-bounds write (buffer overflow) resulting from insufficient bounds validation in the bootloader, appearing in multiple code locations. The attack vector is local, requiring system execution privileges. Exploitation allows privilege escalation to gain unrestricted control at the firmware level. Google released patches on the 2026-09-05 security patch level for all supported Pixel devices, available through the standard device update mechanism.
Affected products
- Google Pixel All supported versions prior to 2026-09-05 security patch level
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched