Executive brief
Google Pixel devices contain a time-of-check to time-of-use (TOCTOU) race condition in the GSA (Google Security Architecture) component that allows an attacker with system execution privileges to escalate their access. This vulnerability could enable unauthorized access to sensitive device functions and data, potentially compromising the security of personal information stored on affected Pixel phones.
Technical details
A race condition in the Google Security Architecture (GSA) component creates a time-of-check to time-of-use (TOCTOU) vulnerability where a permissions check performed at one point in time may be invalidated by the time the protected operation is executed. An attacker with system-level execution privileges can exploit this window to perform privileged operations without proper authorization. The attack vector is local and does not require user interaction. Patches are available through the 2026-09-05 security patch level for supported Pixel devices.
Affected products
- Google Pixel Before 2026-09-05 security patch
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched