Junglewise Threat Intelligence

CVE-2026-58726: Google Pixel GPCA permission bypass in FsmReleaseKey

CVE-2026-58726 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

A security flaw in the Google Pixel's GPCA (a core system component) allows a local attacker with system-level privileges to bypass permission checks in a function called FsmReleaseKey. An attacker exploiting this vulnerability could escalate their privileges within the device, potentially gaining unauthorized access to sensitive system resources or data without requiring user interaction.

Technical details

This is a privilege escalation (EoP) vulnerability caused by a missing permission check in the FsmReleaseKey function within fsm.c, a component of Google Pixel's GPCA (likely a security-related processor component). The vulnerability requires System execution privileges to trigger but enables escalation beyond that level. The attack vector is local and requires no user interaction. Google addressed this issue in the September 2026 security patch (2026-09-05 patch level) available through standard device updates.

Affected products

  • Google Pixel firmware Prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats