Junglewise Threat Intelligence

CVE-2026-57006: Google Pixel ACFW information disclosure due to logic error

CVE-2026-57006 · Severity: medium · CVSS 4.4 · Published 2026-09-15

Executive brief

A logic error in Google Pixel firmware's ACFW (Advanced Core Firmware) component allows local attackers with system-level privileges to read sensitive secrets from device memory. This vulnerability could expose cryptographic keys, authentication tokens, or other confidential data stored by the firmware. The flaw requires local access but no user interaction, making it a risk in scenarios where attackers gain system-level code execution.

Technical details

The vulnerability is a logic error in acfw_ffa.c that permits unauthorized secret reads from firmware memory. The affected component is part of the Pixel device bootloader/firmware stack, and exploitation requires attainment of system execution privileges (e.g., via a prior privilege escalation or code execution vulnerability). The flaw does not require user interaction. An attacker with local system access can trigger the faulty logic path to extract secrets. Patches addressing this issue are available in Pixel security updates from September 5, 2026 onwards.

Affected products

  • Google Pixel prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed: Published in Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses the issue

References

Related threats