Executive brief
Google Pixel devices include a Goodix fingerprint sensor trusted application that processes biometric authentication. A heap buffer overflow in the configuration function could allow a local attacker to escalate privileges and bypass security protections without requiring any special permissions or user interaction.
Technical details
A heap buffer overflow vulnerability exists in the gf_ta_test_set_config function of gf_ta_test.c in the Goodix Fingerprint Trusted Application (TA) due to a logic error in bounds checking. The vulnerability is locally exploitable and requires no additional execution privileges; user interaction is not needed. An attacker with local access can trigger the overflow to corrupt heap memory and achieve privilege escalation. Google released patches as part of the September 2026 security update (patch level 2026-09-05) for all supported Pixel devices.
Affected products
- Google Goodix Fingerprint TA Multiple Pixel devices, patched in 2026-09-05 security update
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched