CVE-2026-56945
massConfused-deputy out-of-bounds write in Google VPU enables local privilege escalation
CVE-2026-56945 is an out-of-bounds write (CWE-787) in Google's VPU (video processing unit) component caused by a confused deputy condition (CWE-441), where the VPU performs memory writes on behalf of a caller without adequately validating the request. A local attacker already holding low privileges on the device — for example, an unprivileged malicious application — can trigger the flaw with no user interaction and no additional execution privileges. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). The CVE was assigned by Google's device security CNA ([email protected]), indicating Google hardware/software — historically components such as the VPU in Tensor-based Pixel devices — though the advisory data does not enumerate exact product or version ranges. No public proof of concept is known, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Apply the latest Google/Android security patch level as soon as the fix ships, since the remediation is expected in a monthly security bulletin; verify the patch level under Settings > System > System update on managed devices. Until patched, restrict sideloading and installation of untrusted apps, since exploitation requires only a low-privileged local app with no user interaction. Watch Google's Android Security Bulletin for the fixed build identifiers and confirm all fleet devices exceed them.
| Google VPU (video processing unit) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-441, CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.