Junglewise Threat Intelligence

CVE-2026-56992: Google Pixel permission bypass in AP ROM

CVE-2026-56992 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

A permission bypass vulnerability in Google Pixel devices' AP ROM firmware could allow a local attacker to escalate privileges to system level. An attacker with local access to a Pixel phone could exploit this confused deputy vulnerability to gain full system execution privileges, potentially compromising all data and functionality on the device.

Technical details

This vulnerability is a confused deputy permission bypass affecting multiple files in the AP ROM (Application Processor Read-Only Memory) component of Google Pixel devices. The vulnerability requires system execution privileges for exploitation but does not require user interaction. The issue allows local privilege escalation through improper permission checks across multiple files. Google has issued security patches with the 2026-09-05 patch level for all supported Pixel devices.

Affected products

  • Google Pixel Before 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Security patch available for all supported Pixel devices

References

Related threats