Junglewise Threat Intelligence

CVE-2026-58695: Google Pixel CPM privilege escalation in phy_power.c

CVE-2026-58695 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

Google Pixel devices contain a firmware vulnerability in the CPM (clock/power management) component that allows a local attacker with system-level privileges to escalate their access further. The flaw stems from improper bounds checking in the phy_power.c code, which could allow an attacker to corrupt or manipulate power management operations. This could result in unauthorized system-level control, compromising device security and user data.

Technical details

The vulnerability is a local privilege escalation (EoP) in the Google Pixel CPM firmware component, specifically in the gmc_phy_lp3_exit_restore_registers function of phy_power.c. The root cause is a missing bounds check that allows an out-of-bounds write or read operation. The attack requires system-level execution privileges and no user interaction. An attacker with system execution privileges can exploit this to achieve further privilege escalation and potentially gain full system control. The vulnerability is addressed in the 2026-09-05 security patch level published on September 15, 2026.

Affected products

  • Google Pixel prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed: Published in Google Pixel Update Bulletin
  • 2026-09-05: patched: Fixed in security patch level 2026-09-05

References

Related threats