CVE-2026-0140
published 2026-06-16CVE-2026-0140: In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no…
PriorityP424high7.5
EPSS
0.18%
7.6th percentile
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android RtpPacket::decodePacket integer overflow
vuldb·2026-06-16
CVE-2026-0140 [CRITICAL] Google Android RtpPacket::decodePacket integer overflow
A vulnerability classified as critical was found in Google Android. This affects the function RtpPacket::decodePacket. The manipulation results in integer overflow.
This vulnerability is identified as CVE-2026-0140. The attack can be executed remotely. There is not any exploit available.
GHSA
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow.
ghsa_unreviewed·2026-06-16
CVE-2026-0140 [MEDIUM] CWE-125 In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow.
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published