CVE-2026-56967
massHeap Buffer Overflow Enables Proximal RCE in Android Cellular Modem
CVE-2026-56967 is an out-of-bounds write (heap buffer overflow, CWE-122) in the Cellular Modem component of Android-family devices, assigned through Google's DSAP vulnerability management program. An attacker on an adjacent network — for example via a rogue cell tower or crafted cellular-network traffic — can trigger the overflow and achieve remote code execution in the modem/baseband context without needing any additional privileges or any user interaction. Successful exploitation carries high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.0, attack vector: adjacent). Devices shipping the vulnerable modem component are affected, though the specific chipset vendors, device models, and firmware versions were not specified in the available data and must be confirmed via the vendor's advisory. No public proof-of-concept is known, the flaw is not on the CISA KEV catalog, and there is no evidence of exploitation in the wild.
What to do: Install the Android security update or carrier/OEM modem firmware patch that remediates this CVE as soon as it ships, and verify the vendor's advisory to identify affected chipset and firmware versions. Because the attack requires network adjacency (e.g., proximity via a rogue base station), high-value users and organizations operating in contested RF environments should treat this as a priority patch; end users cannot disable the modem, so timely updates are the primary mitigation. Monitor the Google Android security bulletin and CISA KEV for updates on affected devices or emerging exploitation.
| Google (via DSAP / Android ecosystem) Cellular Modem component (baseband firmware on Android devices) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.