CVE-2026-0141
published 2026-06-16CVE-2026-0141: In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no…
PriorityP427high7.5
EPSS
0.20%
10.0th percentile
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android RtcpAppPacket.cpp decodeAppPacket out-of-bounds
vuldb·2026-06-16
CVE-2026-0141 [CRITICAL] Google Android RtcpAppPacket.cpp decodeAppPacket out-of-bounds
A vulnerability, which was classified as critical, has been found in Google Android. This vulnerability affects the function decodeAppPacket of the file RtcpAppPacket.cpp. This manipulation causes out-of-bounds read.
This vulnerability is tracked as CVE-2026-0141. The attack is possible to be carried out remotely. No exploit exists.
GHSA
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check.
ghsa_unreviewed·2026-06-16
CVE-2026-0141 [MEDIUM] CWE-120 In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check.
In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published