CVE-2026-0165
published 2026-06-16CVE-2026-0165: In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information…
PriorityP425
EPSS
0.17%
6.7th percentile
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android RTCP Packet out-of-bounds
vuldb·2026-06-16
CVE-2026-0165 [CRITICAL] Google Android RTCP Packet out-of-bounds
A vulnerability classified as critical has been found in Google Android. This issue affects some unknown processing of the component RTCP Packet Handler. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-0165. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check.
ghsa_unreviewed·2026-06-16
CVE-2026-0165 [MEDIUM] CWE-120 In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check.
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published