Executive brief
The IP Multimedia Subsystem (IMS) is a core component in Google Pixel devices that handles voice, video, and messaging services. A bounds-check error allows a remote attacker to write data beyond allocated memory without requiring user interaction or special privileges, potentially leading to remote code execution on affected devices.
Technical details
The vulnerability is an out-of-bounds write in the IP Multimedia Subsystem caused by an incorrect bounds check. The flaw allows remote code execution with no additional execution privileges required and needs no user interaction for exploitation. The attack vector is network-based. Google has issued patches as part of the 2026-09-05 security patch level for affected Pixel devices.
Affected products
- Google Pixel All supported versions prior to 2026-09-05 security patch level
Timeline
- 2026-09-15: disclosed: Published in Google Pixel Security Bulletin for September 2026
- 2026-09-05: patched: Addressed in 2026-09-05 security patch level