CVE-2026-0129

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

16 Sep 2026, 17:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 4.3

Information

Published : 2026-06-16 20:16

Updated : 2026-09-16 17:17


NVD link : CVE-2026-0129

Mitre link : CVE-2026-0129

CVE.ORG link : CVE-2026-0129


JSON object : View

Products Affected

google

  • android
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')