Junglewise Threat Intelligence

CVE-2026-0155: Google libpixelimsmedia out-of-bounds read in ReadByteBuffer

CVE-2026-0155 · Severity: info · CVSS 7.5 · Published 2026-06-16

Technologies: Google Libpixelimsmedia. Vendors: Google.

Executive brief

A security vulnerability exists in a media processing library used by Google Pixel devices. This flaw allows a remote attacker to access sensitive information from the device's memory without any user interaction. This could lead to the exposure of private data or help facilitate further attacks on the device.

Technical details

An out-of-bounds (OOB) read vulnerability exists in the ImsMediaBitReader::ReadByteBuffer function within the libpixelimsmedia library on Google Pixel devices. The flaw is caused by a missing bounds check when reading from a buffer, which can be triggered remotely. An attacker can exploit this to read sensitive data from the process memory. The vulnerability does not require any special execution privileges or user interaction. Google addressed this issue in the June 2026 Pixel Security Bulletin; users should update to the June 5, 2026 patch level or later.

Affected products

  • Google libpixelimsmedia Android versions prior to June 2026 patch level

Timeline

  • 2026-06-16: advisory: NVD and Google Pixel Bulletin published
  • 2026-06-05: patched: Security patch level date for fix

References

Related threats