Junglewise Threat Intelligence

CVE-2026-58734: Google Pixel GDMC out-of-bounds write due to race condition

CVE-2026-58734 · Severity: high · CVSS 7 · Published 2026-09-15

Executive brief

Google Pixel devices contain a race condition vulnerability in the GDMC (Google Device Management Component) that allows a local attacker to write data outside allocated memory boundaries. An attacker with access to a Pixel device can exploit this flaw to escalate their privileges without needing to execute additional code, resulting in unauthorized control over the device and potential access to sensitive user data.

Technical details

The vulnerability exists in the google_mba_recv_msg function within google_mba_poll.c of the GDMC component, where a race condition enables an out-of-bounds write. This memory safety issue is triggered without additional execution privileges or user interaction. The attack vector is local, accessible to any user on the device. Exploitation results in privilege escalation, potentially allowing an attacker to compromise system integrity and access protected data. The vulnerability is addressed in Pixel devices receiving the 2026-09-05 security patch level or later.

Affected products

  • Google Pixel Pre-2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats