Junglewise Threat Intelligence

CVE-2026-56985: Google Pixel KeyMint type confusion privilege escalation

CVE-2026-56985 · Severity: high · CVSS 8.4 · Published 2026-09-15

Executive brief

KeyMint is Google Pixel's cryptographic key management system that secures sensitive operations like digital signatures. A type confusion flaw in multiple files allows attackers to bypass signature protections and gain elevated device privileges without needing to exploit other vulnerabilities or trick users. This could allow an attacker with basic device access to compromise the entire security of Pixel devices.

Technical details

A type confusion vulnerability exists in the KeyMint component on Google Pixel devices, affecting multiple files and allowing attackers to forge or obtain signatures improperly. The vulnerability requires only local access to the affected device and no additional execution privileges. The flaw permits local escalation of privilege with no user interaction required. Google released patches as part of the September 2026 security update with patch level 2026-09-05 or later, addressing this critical issue in the KeyMint trusted execution environment.

Affected products

  • Google Pixel Firmware Earlier than 2026-09-05

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats