Junglewise Threat Intelligence

CVE-2026-0148: Google Pixel RCE via integer overflow in IP Multimedia Subsystem

CVE-2026-0148 · Severity: info · CVSS 8.8 · Published 2026-06-16

Vendors: Google.

Executive brief

A security vulnerability exists in Google Pixel devices within the component responsible for handling multimedia communications. An attacker could remotely execute malicious code on a device without any user interaction or special permissions. This could lead to a complete compromise of the device, including unauthorized access to personal data and system functions.

Technical details

An integer overflow vulnerability exists in multiple functions within VideoRtpPayloadDecoderNode.cpp, part of the IP Multimedia Subsystem (IMS) in Google Pixel devices. This flaw leads to an out-of-bounds write during the processing of Video RTP payloads. The vulnerability is reachable over the network and requires no authentication or user interaction. Successful exploitation allows for remote code execution (RCE) with the privileges of the media processing service. Google addressed this in the June 2026 Pixel Update Bulletin with security patch level 2026-06-05.

Affected products

  • Google Pixel Devices updated before June 5, 2026 patch level

Timeline

  • 2026-06-16: disclosed: NVD publication date
  • 2026-06-16: advisory: Google Pixel Update Bulletin published
  • 2026-06-05: patched: Security patch level date for fix

References