Executive brief
A security vulnerability exists in the audio processing component of Google Pixel devices. An attacker could remotely cause the device's telephony or audio services to crash, leading to a denial of service. This issue does not require any user interaction or special privileges to exploit, potentially disrupting communication capabilities on affected smartphones.
Technical details
A memory safety vulnerability exists in the 'writeAocCommand' function within 'AocAudioCodec.cpp' on Google Pixel devices. The flaw is caused by a missing bounds check when processing audio commands, which can result in an out-of-bounds memory access. A remote attacker can exploit this vulnerability without any prior authentication or user interaction to trigger a denial of service (DoS) condition. The issue specifically affects the Telephony sub-component. Google has addressed this in the June 2026 Pixel Security Bulletin; devices with a patch level of 2026-06-05 or later are protected.
Affected products
- Google Pixel Security patch levels before 2026-06-05
Timeline
- 2026-06-16: disclosed: NVD publication date
- 2026-06-16: advisory: Google Pixel Update Bulletin published
- 2026-06-05: patched: Security patch level date addressing the issue