Junglewise Threat Intelligence

CVE-2026-58683: Google Pixel IP Multimedia Subsystem out-of-bounds write

CVE-2026-58683 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

The IP Multimedia Subsystem (IMS), which handles voice and video calling on Google Pixel devices, contains an out-of-bounds write vulnerability due to improper input validation. An attacker on the network can exploit this flaw to execute arbitrary code remotely with no user interaction required, potentially gaining full control of the affected device and compromising stored data or device functionality.

Technical details

CVE-2026-58683 is an out-of-bounds write vulnerability in the IP Multimedia Subsystem (Telephone subcomponent) on Google Pixel devices, caused by improper input validation. The vulnerability allows remote code execution (RCE) with no authentication or additional execution privileges required, and exploitation does not require user interaction. An attacker can send specially crafted network packets to trigger the out-of-bounds write, enabling arbitrary code execution at the Telephone service privilege level. Google released patches as part of the September 2026 security update (patch level 2026-09-05), addressing this and related vulnerabilities affecting Pixel devices.

Affected products

  • Google Pixel Before 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Security patch level 2026-09-05 addresses all issues in bulletin

References

Related threats