CVE-2026-0128

⚪ Do wiadomości

Przepełnienie bufora w RtcpFbPacket umożliwia zdalne ujawnienie informacji.

CVSS
6.5
EPSS
0.2%
Exploit
none
Vendor
google
Opis źródłowy (NVD)

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-06-16 20:16:23 UTC
Ostatnia modyfikacja (NVD)2026-09-16 17:17:12 UTC
Referencje