Junglewise Threat Intelligence

CVE-2026-56974: Google Pixel libpixelimsmedia out-of-bounds write in AudioRtpPayloadEncoderNode

CVE-2026-56974 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Google Pixel devices contain a vulnerable audio processing library (libpixelimsmedia) used to encode real-time multimedia streams. A flaw in the AudioRtpPayloadEncoderNode component allows an attacker to write data beyond allocated memory boundaries through improper input validation. An attacker can exploit this to execute arbitrary code on affected devices with no additional privileges, though user interaction is required to trigger the vulnerability.

Technical details

The vulnerability is an out-of-bounds write caused by improper input validation in the AudioRtpPayloadEncoderNode.cpp file within Google's libpixelimsmedia library. The flaw allows an attacker to write to memory outside the intended buffer boundaries, potentially enabling code execution. The vulnerability requires user interaction to exploit (e.g., processing a specially crafted audio stream), but once triggered, permits remote code execution without requiring elevated privileges. The Pixel Update Bulletin for September 2026 (patch level 2026-09-05 or later) addresses this issue.

Affected products

  • Google Pixel devices Pre-2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed: Published in Pixel Update Bulletin
  • 2026-09-05: patched: Addressed in 2026-09-05 patch level and later

References

Related threats