CVE-2026-0140: Integer Overflow
Published Jun 16, 2026
·Updated
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Jun 16, 2026
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0140?
CVE-2026-0140 has a medium severity rating of 4.3.
2
What type of vulnerability is CVE-2026-0140?
CVE-2026-0140 is classified as an integer overflow vulnerability.
3
What risks are involved with CVE-2026-0140?
CVE-2026-0140 may lead to remote information disclosure if successfully exploited.
4
How can CVE-2026-0140 be mitigated?
To mitigate CVE-2026-0140, ensure that your Google Android software is regularly updated to the latest version.
5
What is required for the exploitation of CVE-2026-0140?
User interaction is required to exploit CVE-2026-0140.