Executive brief
A security vulnerability exists in a media processing library used by Google Pixel devices. This component handles real-time communication protocols, and the flaw allows a remote attacker to access sensitive information from the device's memory without any user interaction. This could lead to the exposure of private data or system information that could be used in further attacks.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the 'RtcpHeader::decodeRtcpHeader' function within the 'libpixelimsmedia' library on Google Pixel devices. The flaw is caused by a missing bounds check during the decoding of RTCP (Real-time Control Protocol) headers. A remote, unauthenticated attacker can exploit this by sending specially crafted network packets to trigger an out-of-bounds memory access. Successful exploitation results in the disclosure of sensitive information from the process memory. The issue is addressed in the June 2026 Pixel security update (patch level 2026-06-05).
Affected products
- Google libpixelimsmedia Android versions prior to 2026-06-05 patch level
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-05: patched