Executive brief
Google Pixel devices contain a use-after-free vulnerability in the kernel caused by a race condition in multiple locations. An attacker with local system access can exploit this to achieve privilege escalation and execute code with system-level permissions. This impacts the security of Pixel devices as it allows a local attacker to gain complete control of the device.
Technical details
The vulnerability is a use-after-free condition arising from a race condition in multiple kernel locations. The flaw allows an attacker with local system execution privileges to trigger memory corruption by accessing freed memory concurrently. No user interaction is required for exploitation. The vulnerability affects Pixel devices and is patched in the 2026-09-05 security patch level. This is a classic memory safety issue that enables local privilege escalation to system level.
Affected products
- Google Pixel Pre-2026-09-05 patch level
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched