Executive brief
A vulnerability exists in the Exynos Multi-Format Codec (MFC) used in Google Pixel devices. This component is responsible for processing video data. A remote attacker could exploit this flaw to execute unauthorized code on the device without any user interaction, potentially leading to full device compromise or data theft.
Technical details
An out-of-bounds write vulnerability exists in the Exynos Multi-Format Codec (MFC) component of Google Pixel devices, specifically within the '__mfc_core_nal_q_get_dec_metadata_sei_nal' function in 'mfc_core_nal_q.c'. The flaw is caused by a missing bounds check when processing NAL (Network Abstraction Layer) units. An attacker can exploit this to achieve remote code execution (RCE) with no additional privileges or user interaction required. The vulnerability was addressed in the June 2026 Pixel Security Bulletin.
Affected products
- Google Pixel Security patch levels before 2026-06-05
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later contains the fix.