ZeroHour

CVE-2026-56882

mass

Logic Error in Android Cellular Modem Firmware Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-56882 is a logic error in the Cellular Modem component of Android that results in information disclosure, which can be chained to achieve remote code execution in the modem (baseband) context with no additional execution privileges required. Because the flaw resides in modem firmware and exploitation requires no user interaction, an attacker on the same network path — or positioned to send crafted cellular/network traffic — could trigger the bug and execute code on the target device, subject to the low-privilege prerequisite described in the CVSS vector (PR:L). The vulnerability affects Android devices whose baseband firmware contains the flawed code, with fixes distributed via Google's Android security bulletin and OEM/carrier modem firmware updates. The flaw is rated high severity (CVSS 3.1: 8.8), but no public proof-of-concept exists and it is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the latest Android security bulletin patch level and any accompanying OEM/carrier modem firmware update, since baseband fixes are typically delivered through the vendor's OTA channel rather than app stores. Prioritize flagship and carrier-managed fleets that receive modem firmware updates directly, and verify the device's current security patch level in Settings. Monitor vendor advisories for the bulletin that remediates this CVE and watch for anomalous baseband crashes or modem resets, which can indicate exploitation attempts.

Affected
Google (Android) Android - Cellular Modem component
Estimated exposure
masspotentially hundreds of millions of Android devices (clearly an estimate) — Android runs on roughly 3 billion active devices and virtually all of them include a cellular modem component, though the actually-vulnerable population is smaller and shrinking as OEM/carrier firmware updates roll out.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.