Junglewise Threat Intelligence

CVE-2026-0131: Google Pixel libpixelimsmedia integer overflow in RtpPacket::decodePacket

CVE-2026-0131 · Severity: info · CVSS 7.8 · Published 2026-06-16

Technologies: Google Pixel Firmware. Vendors: Google.

Executive brief

A security vulnerability exists in the media handling component of Google Pixel devices. This flaw could allow a local attacker to gain elevated system privileges, potentially leading to unauthorized access to sensitive data or control over device functions. Exploitation requires a user to interact with a malicious file or application.

Technical details

An integer overflow vulnerability exists within the 'RtpPacket::decodePacket' function of the 'libpixelimsmedia' component in Google Pixel devices. This flaw leads to an out-of-bounds memory access when processing specially crafted Real-time Transport Protocol (RTP) packets. A local attacker can exploit this to achieve escalation of privilege (EoP) without requiring prior elevated permissions, though user interaction is a prerequisite for the attack. The issue is addressed in the June 2026 Pixel security update (patch level 2026-06-05).

Affected products

  • Google Pixel Firmware prior to 2026-06-05 patch level

Timeline

  • 2026-06-16: disclosed
  • 2026-06-05: patched: Security patch level date

References

Related threats