CVE-2026-0200
massHeap Buffer Overflow in Cellular Modem Component Enables Remote Privilege Escalation
CVE-2026-0200 is a heap-based out-of-bounds write (CWE-122/CWE-787) in the Cellular Modem component disclosed via Google's Android/device vulnerability management program. An attacker who already has low-level privileges can trigger the overflow with crafted input over the network, with no user interaction required, and escalate privileges on the affected device with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Devices running modem firmware containing the flawed code path are affected; the exact vendor, chipset, and version range were not specified in the available data. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is not known to have occurred. Defenders should treat it as a high-priority patch target for mobile/connected devices once vendor bulletins identify the fixed firmware or OS builds.
What to do: Monitor the Google/Android Security Bulletin and your device OEM's and modem chipset vendor's advisories for the fixed firmware or security patch level, and deploy carrier/OEM updates as soon as they are released. Until affected versions are identified, prioritize patching speed for mobile fleets and embedded devices with cellular radios, and verify with vendors whether their modem firmware includes this fix. No workaround is documented, so timely firmware patching is the primary mitigation.
| Google (Android device security program - [email protected]) Cellular Modem | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-122, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.