Junglewise Threat Intelligence

CVE-2026-58698: Google Pixel firmware permission bypass in AP PMIC handler

CVE-2026-58698 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

Google Pixel devices contain a vulnerability in the AP PMIC (application processor power management IC) firmware component that allows local attackers with system-level privileges to bypass permission checks through a confused deputy attack. Successful exploitation could enable attackers to escalate privileges or gain unauthorized access to system functions, potentially compromising device integrity and security.

Technical details

A confused deputy vulnerability exists in the ap_pmic_poll_msg_handler function of ap_pmic_ipc.c, where improper permission validation allows a local attacker to bypass authorization checks. The vulnerability requires System execution privileges but does not require user interaction for exploitation. This is a classic confused deputy scenario where a privileged handler fails to properly validate the authority of a caller before performing a sensitive operation. The attack can lead to local privilege escalation. A fix is available in the Pixel Update Bulletin with security patch level 2026-09-05 or later.

Affected products

  • Google Pixel firmware Prior to 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses this issue

References

Related threats