Impact
The vulnerability resides in the Cellular Modem component where a missing bounds check allows an out‑of‑bounds write. This flaw enables an attacker to overwrite memory beyond the intended boundary, leading to remote code execution without requiring any additional privileges or user interaction. The vulnerability can be triggered by an adversary capable of influencing the modem stack remotely.
Affected Systems
Google Android devices that include the vulnerable cellular modem firmware. Specific affected Android versions are not disclosed in the available data, so any device running the affected modem build is potentially at risk.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity, and combined with the fact that no user interaction is required, the potential impact on confidentiality, integrity, and availability is significant. The EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS and lack of interaction requirements mean that exploitation could be feasible if an attacker is able to target the modem stack.
OpenCVE Enrichment