Junglewise Threat Intelligence

CVE-2026-0129: Google Pixel libpixelimsmedia information disclosure in decodeByePacket

CVE-2026-0129 · Severity: info · CVSS 7.5 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in Google Pixel devices within a component responsible for handling media communications. If a user is tricked into interacting with a malicious media stream, an attacker could potentially access sensitive information from the device's memory. This could lead to the exposure of private data, though it does not allow the attacker to take full control of the device.

Technical details

An information disclosure vulnerability exists in the libpixelimsmedia component of Google Pixel devices. The flaw is located in the RtcpByePacket::decodeByePacket function and is caused by a missing bounds check when processing RTCP (Real-time Transport Control Protocol) BYE packets. A remote attacker can exploit this by sending a specially crafted packet, which, upon processing, could lead to an out-of-bounds read. Successful exploitation requires user interaction and can result in the disclosure of sensitive information from the process memory. The issue is addressed in the June 2026 Pixel security update.

Affected products

  • Google Pixel Prior to June 2026 security patch level

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later fixes this issue.

References