Junglewise Threat Intelligence

CVE-2026-56972: Google Pixel bootloader out-of-bounds write

CVE-2026-56972 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

Google Pixel devices contain an out-of-bounds memory write vulnerability in the bootloader firmware due to incorrect bounds checking. An attacker with system-level access can exploit this to escalate privileges and gain complete control of the device. The vulnerability affects all Pixel devices until patched with the September 2026 security update.

Technical details

The vulnerability is a classic out-of-bounds write (buffer overflow) resulting from insufficient bounds validation in the bootloader, appearing in multiple code locations. The attack vector is local, requiring system execution privileges. Exploitation allows privilege escalation to gain unrestricted control at the firmware level. Google released patches on the 2026-09-05 security patch level for all supported Pixel devices, available through the standard device update mechanism.

Affected products

  • Google Pixel All supported versions prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats