Executive brief
A use-after-free vulnerability in the IP Multimedia Subsystem (which handles voice and video calls) on Google Pixel devices allows remote attackers to execute arbitrary code without authentication or user interaction. An attacker could exploit this to gain full control over the device, potentially intercepting calls, accessing personal data, or installing malware.
Technical details
A use-after-free due to a race condition exists in the IP Multimedia Subsystem component of Google Pixel devices. The vulnerability is triggered remotely with no authentication or user interaction required. An attacker can send specially crafted network traffic to trigger the race condition, causing freed memory to be accessed and allowing remote code execution with the privileges of the IMS process. The issue is addressed by security patches at Android patch level 2026-09-05 or later.
Affected products
- Google Pixel All supported Pixel devices prior to 2026-09-05 patch level
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched