ZeroHour

CVE-2026-0200

mass

Heap Buffer Overflow in Cellular Modem Component Enables Remote Privilege Escalation

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-0200 is a heap-based out-of-bounds write (CWE-122/CWE-787) in the Cellular Modem component disclosed via Google's Android/device vulnerability management program. An attacker who already has low-level privileges can trigger the overflow with crafted input over the network, with no user interaction required, and escalate privileges on the affected device with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). Devices running modem firmware containing the flawed code path are affected; the exact vendor, chipset, and version range were not specified in the available data. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is not known to have occurred. Defenders should treat it as a high-priority patch target for mobile/connected devices once vendor bulletins identify the fixed firmware or OS builds.

What to do: Monitor the Google/Android Security Bulletin and your device OEM's and modem chipset vendor's advisories for the fixed firmware or security patch level, and deploy carrier/OEM updates as soon as they are released. Until affected versions are identified, prioritize patching speed for mobile fleets and embedded devices with cellular radios, and verify with vendors whether their modem firmware includes this fix. No workaround is documented, so timely firmware patching is the primary mitigation.

Affected
Google (Android device security program - [email protected]) Cellular Modem
Estimated exposure
massPotentially hundreds of millions of devices (upper bound); exact count unknown pending affected-version disclosure — Cellular modem components ship in essentially all of the ~3 billion active Android and connected devices worldwide, so the upper bound is mass-scale, though the true figure depends on the undisclosed vendor and firmware version range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.