CVE-2026-0127
published 2026-06-16CVE-2026-0127: In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote…
PriorityP430
EPSS
0.25%
16.7th percentile
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption.
ghsa_unreviewed·2026-06-16
CVE-2026-0127 [MEDIUM] CWE-125 In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption.
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for exploitation.
VulDB
Google Android cn_NrmmDecoder.cpp DecodeUPUTransparentContext out-of-bounds
vuldb·2026-06-16
CVE-2026-0127 [CRITICAL] Google Android cn_NrmmDecoder.cpp DecodeUPUTransparentContext out-of-bounds
A vulnerability marked as critical has been reported in Google Android. The impacted element is the function NrmmMsgCodec::DecodeUPUTransparentContext of the file cn_NrmmDecoder.cpp. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-0127. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published