Junglewise Threat Intelligence

CVE-2026-0141: Google Pixel Telephony out-of-bounds read in RtcpAppPacket

CVE-2026-0141 · Severity: info · CVSS 7.5 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in the telephony component of Google Pixel devices. This flaw allows a remote attacker to access sensitive information from the device's memory without any user interaction. This could lead to the exposure of private data or system information that should remain protected.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the 'decodeAppPacket' function within 'RtcpAppPacket.cpp' of the Google Pixel telephony component. The issue stems from a missing bounds check when processing RTCP (Real-time Transport Control Protocol) application packets. A remote attacker can exploit this flaw over the network to read sensitive information from the process memory. No elevated privileges or user interaction are required for exploitation. Google has addressed this in the June 2026 security patch for Pixel devices.

Affected products

  • Google Pixel Updates prior to June 2026 patch level

Timeline

  • 2026-06-16: disclosed: Vulnerability details published in Google Pixel Update Bulletin and NVD.
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References