CVE-2026-0159
massOut-of-Bounds Write in Android Cellular Modem Firmware Enables Remote Code Execution
CVE-2026-0159 is an out-of-bounds write (CWE-787) caused by a missing bounds check in the Cellular Modem component of Google-managed mobile device firmware, disclosed via Google's Android/Pixel vulnerability management CNA. The flaw is remotely exploitable over the network with low privileges required, no user interaction, and low attack complexity, allowing an attacker to achieve remote code execution with no additional execution privileges needed. Successful exploitation would impact confidentiality, integrity, and availability of the affected device (CVSS 3.1: 8.8, high). Any devices running the vulnerable modem firmware are affected; exact version ranges were not specified in the available data, so defenders should consult the vendor's security bulletin. There is no known public proof of concept and the CVE is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Install the latest Android/Pixel security update containing the modem firmware fix as soon as it is available via OTA, and verify the device's security patch level in Settings. Fleet and MDM administrators should check modem/baseband firmware versions against the vendor advisory and prioritize this patch given that exploitation requires no user interaction. Monitor the Google security bulletin for the fixed build identifiers and any indicators of exploitation.
| Google Cellular Modem (Android/Pixel modem firmware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.