Executive brief
A vulnerability exists in the video processing component of certain Google Pixel devices. This flaw allows a remote attacker to execute unauthorized code on the device without any user interaction. This could lead to a complete compromise of the device, including theft of personal data or loss of operational control.
Technical details
An out-of-bounds write vulnerability exists in the 'mfc_core_get_dec_metadata_sei_nal' function within 'mfc_core_reg_api.c' of the Exynos Multi-Format Codec (MFC) driver. The root cause is a missing bounds check when processing Supplemental Enhancement Information (SEI) Network Abstraction Layer (NAL) units in video streams. A remote attacker can exploit this by providing specially crafted video metadata, leading to memory corruption. This can be leveraged for remote code execution (RCE) with no privileges or user interaction required. The issue is addressed in the June 2026 Pixel Security Bulletin.
Affected products
- Samsung Exynos MFC Pixel devices with security patch levels before 2026-06-05
Timeline
- 2026-06-05: patched: Security patch level required to address the issue.
- 2026-06-16: advisory: NVD and Google Pixel security bulletin published.