Junglewise Threat Intelligence

CVE-2026-0162: Google Pixel type confusion in AudioSdpParser

CVE-2026-0162 · Severity: info · CVSS 9.8 · Published 2026-06-16

Vendors: Google.

Executive brief

A vulnerability exists in the way Google Pixel devices process audio data during multimedia sessions. An attacker could exploit this to remotely take control of the device or cause it to crash without any interaction from the user. This affects the privacy of user data and the overall availability of the mobile service.

Technical details

A type confusion vulnerability exists in the 'ParsePayloads' function within 'AudioSdpParser.cpp', part of the IP Multimedia Subsystem (IMS) on Google Pixel devices. The flaw occurs during the parsing of Session Description Protocol (SDP) payloads, leading to memory corruption. An unauthenticated remote attacker can exploit this over the network to achieve remote code execution (RCE) or a denial of service (DoS) state. No execution privileges or user interaction are required for successful exploitation. The issue is addressed in the June 2026 Pixel security update (patch level 2026-06-05).

Affected products

  • Google Pixel Security patch level before 2026-06-05

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-05: patched

References