Vulnerability Details CVE-2026-0149
In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 19.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-0149
-
cpe:2.3:o:google:android:-