PT-2026-49815 · Google · Android

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-0157

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Fix

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-0157

Affected Products

Android