Executive brief
A security vulnerability exists in the media processing library used by Google Pixel devices. This flaw could allow a remote attacker to access sensitive information from the device's memory if a user interacts with a specially crafted media stream. This could lead to the exposure of private data or help facilitate further attacks on the device.
Technical details
An out-of-bounds read vulnerability exists in the RTCP (Real-time Transport Control Protocol) packet decoder within the libpixelimsmedia library on Google Pixel devices. The flaw is caused by missing bounds checks in several decoding functions. A remote attacker can exploit this by sending malformed RTCP packets, which, upon processing, allows for the disclosure of sensitive information from the process memory. Exploitation requires user interaction, likely in the context of a multimedia session or call. The issue is addressed in the June 2026 Pixel Security Bulletin with patch levels 2026-06-05 or later.
Affected products
- Google libpixelimsmedia Android Pixel devices prior to 2026-06-05 patch level
Timeline
- 2026-06-16: disclosed: Vulnerability details published in Google Pixel Update Bulletin
- 2026-06-05: patched: Security patch level released to address the issue