CVE-2026-55331
massOut-of-bounds write enables remote code execution in Android IMS telephony stack
CVE-2026-55331 is an out-of-bounds write (CWE-120) caused by an incorrect bounds check in the IP Multimedia Subsystem (IMS), the 3GPP framework Android devices use for carrier services such as VoLTE, Wi-Fi calling, and RCS messaging. Because the flawed code processes network-sourced IMS/SIP signaling, an attacker with the low level of privileges reflected in the CVSS vector (PR:L) could trigger memory corruption remotely, with no user interaction required. Successful exploitation yields remote code execution without needing additional execution privileges, giving the attacker high impact on confidentiality, integrity, and availability of the affected component. The vulnerability was assigned by Google's device security vulnerability management CNA, indicating the Android platform's IMS implementation, though the specific affected versions were not provided in the available data. No public proof-of-concept exists, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply the latest monthly Android security update or OEM/carrier OTA as soon as Google publishes the fix and vendors ship it, and verify the device's security patch level. Because exploitation flows through IMS/SIP signaling, defenders in carrier environments should monitor for and filter malformed SIP/IMS traffic at the network edge. No workaround is documented, so patching is the primary mitigation.
| Google Android — IP Multimedia Subsystem (IMS) component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.