Junglewise Threat Intelligence

CVE-2026-56982: Google Pixel VPU permission bypass privilege escalation

CVE-2026-56982 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

The Video Processing Unit (VPU) in Google Pixel devices contains a missing permission check that allows an attacker with system-level access to bypass security controls. An exploit could allow unauthorized escalation of privileges to system level, potentially compromising the security and integrity of the device and any data processed through video functionality.

Technical details

This is a privilege escalation vulnerability in the VPU component due to missing permission validation. The vulnerability allows an attacker with existing system execution privileges to bypass permission checks and further escalate their access. The attack vector is local and does not require user interaction. Google released patches in their September 2026 Pixel Update Bulletin with a security patch level of 2026-09-05 or later addressing this issue.

Affected products

  • Google Pixel Before 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats