Junglewise Threat Intelligence

CVE-2026-58721: Google Pixel uninitialized memory information disclosure in GSA

CVE-2026-58721 · Severity: medium · CVSS 4.4 · Published 2026-09-15

Executive brief

Google Pixel devices contain a vulnerability in the Google Security & Analytics (GSA) component that allows local information disclosure through uninitialized memory. An attacker with System-level privileges can read sensitive data from device memory without user interaction. This exposure could reveal device configuration, authentication tokens, or other confidential information stored in memory.

Technical details

The vulnerability is an information disclosure (ID) flaw caused by uninitialized memory use in the GSA (Google Security & Analytics) component of Google Pixel devices. The attack vector is local and requires System execution privileges to exploit. No user interaction is needed for the vulnerability to be triggered. An attacker with system-level access can read uninitialized memory regions to extract sensitive information. The issue was patched in the September 2026 Pixel security update (2026-09-05 patch level or later).

Affected products

  • Google Pixel Before 2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats