Executive brief
A critical security vulnerability exists in Google Pixel devices within the component responsible for processing real-time text communications. An attacker could remotely execute malicious code on a user's device without any interaction from the user. This could lead to a complete compromise of the device, including unauthorized access to sensitive data or loss of control over the phone's functions.
Technical details
An out-of-bounds write vulnerability exists in the 'TextRtpPayloadDecoderNode::DecodeT140' function within 'TextRtpPayloadDecoderNode.cpp' on Google Pixel devices. The flaw is caused by a missing bounds check when decoding T.140 text payloads over RTP (Real-time Transport Protocol). A remote, unauthenticated attacker can exploit this by sending specially crafted network packets to the gIMS (Google IP Multimedia Subsystem) component. Successful exploitation allows for remote code execution (RCE) with no additional privileges or user interaction required. Google has addressed this in the June 2026 Pixel Security Bulletin.
Affected products
- Google Pixel Devices with security patch levels before 2026-06-05
Timeline
- 2026-06-16: disclosed: Vulnerability details published in NVD and Google Pixel Update Bulletin.
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.