Executive brief
A security vulnerability exists in a media processing library used by Google Pixel devices. This component handles Real-time Transport Protocol (RTP) packets, which are commonly used for streaming audio and video. An attacker could potentially exploit this flaw to access sensitive information from the device's memory, though it requires some form of user interaction to occur.
Technical details
A vulnerability exists in the libpixelimsmedia library within the RtpPacket::decodePacket function. The flaw is caused by an integer overflow during the processing of RTP packets, which results in an out-of-bounds read. An attacker can exploit this to disclose sensitive information from the process memory. While the attack vector is remote, exploitation requires user interaction. The issue was addressed in the June 2026 Pixel Update Bulletin, with the fix included in security patch levels 2026-06-05 or later.
Affected products
- Google libpixelimsmedia Android devices with security patch levels before 2026-06-05
Timeline
- 2026-06-16: advisory: Initial publication of the Pixel Update Bulletin and NVD entry.
- 2026-06-05: patched: Security patch level date addressing the issue.