CVE-2026-0157: Medium severity Google Android vulnerability
Published Jun 16, 2026
·Updated
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
1 affected component
Google Android
Event History
Jun 16, 2026
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0157?
The severity of CVE-2026-0157 is assessed as medium with a CVSS score of 4.3.
2
How do I fix CVE-2026-0157?
To fix CVE-2026-0157, update your Google Android device to the latest security patch provided by the manufacturer.
3
What is the impact of CVE-2026-0157?
CVE-2026-0157 can lead to remote information disclosure due to a possible out-of-bounds read.
4
Does CVE-2026-0157 require user interaction for exploitation?
No, CVE-2026-0157 does not require user interaction to be exploited.
5
Which software is affected by CVE-2026-0157?
CVE-2026-0157 affects Google Android software.