CVE-2026-0147
published 2026-06-16CVE-2026-0147: In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to…
PriorityP337
EPSS
0.28%
19.6th percentile
In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android mfc_core_nal_q.c __mfc_core_nal_q_get_dec_metadata_sei_nal out-of-bounds write
vuldb·2026-06-16
CVE-2026-0147 Google Android mfc_core_nal_q.c __mfc_core_nal_q_get_dec_metadata_sei_nal out-of-bounds write
A vulnerability has been found in Google Android and classified as critical. Impacted is the function __mfc_core_nal_q_get_dec_metadata_sei_nal of the file mfc_core_nal_q.c. Performing a manipulation results in out-of-bounds write.
This vulnerability is cataloged as CVE-2026-0147. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check.
ghsa_unreviewed·2026-06-16
CVE-2026-0147 [HIGH] CWE-120 In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check.
In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No writeups or analysis indexed.
2026-06-16
Published