Executive brief
A security vulnerability exists in the telephony component of Google Pixel devices. An attacker could remotely cause the device's communication services to crash or become unresponsive without any user interaction. This impact is limited to a denial of service, potentially disrupting phone calls or messaging capabilities.
Technical details
A memory safety vulnerability exists in the 'checkSsrcCollisionOnRcv' function within 'RtpSession.cpp' of the Android telephony stack. The issue stems from a missing null pointer check, which can be triggered by processing malformed Real-time Transport Protocol (RTP) traffic. A remote, unauthenticated attacker can exploit this to cause a denial of service (DoS) by crashing the affected process. No user interaction or special privileges are required for exploitation. The vulnerability is addressed in the June 2026 Pixel Security Bulletin.
Affected products
- Google Pixel Security patch levels before 2026-06-05
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-05: patched: Security patch level 2026-06-05 or later required.