Junglewise Threat Intelligence

CVE-2026-0128: Google libpixelimsmedia integer overflow in decodeRtcpFbPacket

CVE-2026-0128 · Severity: info · CVSS 7.5 · Published 2026-06-16

Technologies: Google Libpixelimsmedia. Vendors: Google.

Executive brief

A security vulnerability exists in a media processing library used by Google Pixel devices. An attacker could potentially access sensitive information from the device's memory if a user interacts with a specially crafted malicious file or stream. This could lead to the unauthorized disclosure of private data, though it does not allow the attacker to take full control of the device.

Technical details

A vulnerability exists in the libpixelimsmedia component of Google Pixel devices within the RtcpFbPacket::decodeRtcpFbPacket function. The flaw is caused by an integer overflow that leads to an out-of-bounds read during the processing of RTCP Feedback packets. An unauthenticated remote attacker can exploit this by inducing a user to process a malicious packet, potentially resulting in the disclosure of sensitive information from the process memory. While the NVD entry lists the severity as 'info' (awaiting enrichment), the primary vendor (Google) classifies this as 'High' severity (ID/Information Disclosure). A patch is available in the June 2026 Pixel Security Bulletin.

Affected products

  • Google libpixelimsmedia Android Pixel devices prior to 2026-06-05 patch level

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats