Executive brief
A security vulnerability exists in Google Pixel devices within the component responsible for handling real-time media streaming. An attacker could exploit this flaw remotely to gain unauthorized elevated privileges on the device without any interaction from the user. This could allow a malicious actor to bypass security restrictions, access sensitive data, or compromise the integrity of the operating system.
Technical details
An integer overflow vulnerability exists in the 'numberOfReportBlocks' function within 'RtpSession.cpp' of the Real-time Transport Protocol (RTP) implementation on Google Pixel devices. The flaw occurs during the processing of RTP packets, where an integer overflow can trigger an out-of-bounds memory write. This vulnerability is reachable over the network and requires no user interaction or special execution privileges. Successful exploitation allows a remote attacker to achieve escalation of privilege (EoP). The issue is addressed in the June 2026 Pixel security update (patch level 2026-06-05).
Affected products
- Google Pixel Prior to June 2026 security patch level
Timeline
- 2026-06-16: advisory: NVD and Google Pixel Bulletin published
- 2026-06-05: patched: Security patch level date for fix