Junglewise Threat Intelligence

CVE-2026-58691: Google Pixel GPCA permission bypass in fsm.c

CVE-2026-58691 · Severity: high · CVSS 8.4 · Published 2026-09-15

Executive brief

A permission validation flaw in Google Pixel firmware's GPCA component allows a local attacker to escalate privileges without requiring additional execution permissions or user interaction. An attacker with local access could exploit this to gain elevated system privileges, potentially leading to unauthorized access to sensitive device features or data.

Technical details

The vulnerability exists in the FsmReleaseKey function of fsm.c in the GPCA (Google Pixel Component A) subsystem, where improper input validation fails to correctly enforce permission checks. This permits local privilege escalation (EoP) via a permission bypass mechanism. No additional execution privileges are required, and exploitation requires only local access to the device—no user interaction is necessary. The vulnerability was patched in the Pixel security update with patch level 2026-09-05 or later.

Affected products

  • Google Pixel Firmware Prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats