CVE-2026-0130
published 2026-06-16CVE-2026-0130: In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no…
PriorityP425high7.1
EPSS
0.17%
7.0th percentile
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android decodeRtcpChunk heap-based overflow
vuldb·2026-06-16
CVE-2026-0130 Google Android decodeRtcpChunk heap-based overflow
A vulnerability identified as critical has been detected in Google Android. Impacted is the function RtcpChunk::decodeRtcpChunk. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-0130. The attack is possible to be carried out remotely. No exploit exists.
GHSA
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow.
ghsa_unreviewed·2026-06-16
CVE-2026-0130 [LOW] CWE-122 In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow.
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
2026-06-16
Published