CVE-2026-0131
published 2026-06-16CVE-2026-0131: In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no…
PriorityP427
EPSS
0.07%
0.1th percentile
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow.
ghsa_unreviewed·2026-06-16
CVE-2026-0131 [HIGH] CWE-125 In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow.
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
VulDB
Google Android RtpPacket::decodePacket integer overflow
vuldb·2026-06-16
CVE-2026-0131 [CRITICAL] Google Android RtpPacket::decodePacket integer overflow
A vulnerability was found in Google Android. It has been rated as critical. The affected element is the function RtpPacket::decodePacket. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2026-0131. An attack has to be approached locally. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published