News

Pixel Bluetooth flaw enables no-click code execution

Louis Stowasser
Louis Stowasser
Thursday 8 October 2026
Pixel Bluetooth flaw enables no-click code execution
Pixel Bluetooth flaw enables no-click code execution

CVE-2026-55330 is a flaw in the Bluetooth component of Google Pixel device firmware, rather than an Android app or a server that an organisation installs. It matters to anyone responsible for Pixel endpoints: company-owned handsets, work-profile phones and employee-owned devices allowed onto corporate services all put this code in users’ hands.

Google’s CNA description says a logic error creates a use-after-free in BluetoothCccHandlerCallbackImpl, in bluetooth_ccc.cc. A use-after-free occurs when software releases an object but later continues to use it; an attacker who can shape what occupies that memory may be able to redirect program behaviour. Here, the stated outcome is remote code execution with no additional execution privileges and no user interaction. The public CVE record identifies “Android kernel” as affected, though Google’s Pixel bulletin classifies the issue under Bluetooth rather than its separate kernel-components section.

The attack path remains deliberately opaque

“Remote” should not be read as proof that an attacker can strike from anywhere on the internet. Bluetooth generally implies radio proximity, but the public record does not establish the required distance, whether a device must be paired, whether Bluetooth must be enabled and discoverable, or the exact packet or callback sequence that reaches the bug. Those details are important operational boundaries, and they have not been published.

There is also a classification mismatch worth retaining in risk discussions. Google’s Pixel bulletin calls CVE-2026-55330 an elevation-of-privilege issue, while the CNA description says it could lead to remote code execution. The bulletin lists it as Critical and gives Android bug ID A-522372636, but does not publish a CVSS score. The supplied 9.8 vector is a CISA-ADP assessment shown by NVD, whose own entry remains awaiting enrichment.

Google marks the associated bug as non-public; its bulletin says starred issues are generally fixed in the latest binary drivers for Pixel devices. No vendor patch, source diff, or vulnerable-code pattern is public. That means nobody outside Google can presently verify which object is freed, what later dereferences it, or how the fix changes the logic.

Update Pixel fleets rather than chase indicators

A patch exists: Pixel security patch level 2026-10-05 or later addresses the issue. Google does not provide a normal affected-version range, Android-release list, chipset list or model-by-model applicability table, so it cannot be confirmed that every supported Pixel model carries the vulnerable component. Its current support list is useful for update planning, but it is not an affected-model list.

For IT teams, the practical response is to inventory managed and permitted Pixel devices, require the October 2026 patch level or newer through endpoint-management policy where possible, and follow up on devices that cannot update. Review Bluetooth policy as a compensating measure—especially in higher-risk workplaces—but do not present disabling discovery or avoiding pairing as a confirmed mitigation; the trigger is unknown.

As of October 8, 2026, no exploitation in the wild has been confirmed, no public proof of concept or exploit code has surfaced, and CVE-2026-55330 was not in CISA’s Known Exploited Vulnerabilities catalogue. Those are snapshots, not reasons to defer patching a no-interaction memory-safety flaw. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs; use that visibility to keep mobile patch compliance from becoming an afterthought.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203