Description
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Apply Update
AI Analysis

Impact

An out‑of‑bounds write can be triggered by a heap buffer overflow within the Android Cellular Modem, allowing an attacker to write beyond allocated memory. This leads to a remote privilege escalation that does not require any additional execution privileges or user interaction. The vulnerability therefore can grant an attacker elevated rights on the device without needing to compromise a user account or obtain code execution.

Affected Systems

All Google Android devices that incorporate the vulnerable cellular modem firmware are potentially affected, regardless of the OS version or specific firmware build, as no version details are disclosed in the advisory.

Risk and Exploitability

The CVSS score of 8.8 categorises the flaw as high severity, while the EPSS score of <1% indicates a very low yet non‑zero probability of real‑world exploitation. The likely attack vector is remote, inferred from the description that the flaw can be triggered via crafted cellular traffic, and no user interaction is needed. Although the vulnerability is not listed in CISA's KEV catalog, its impact manifests as an ability to bypass normal access controls and obtain elevated privileges on the device.

Generated by OpenCVE AI on September 20, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Android OS update that contains the fix for the cellular modem flaw.
  • If no update is yet available, configure the device to restrict or block privileged modem control interfaces so that external entities cannot send malformed traffic to the radio processor.
  • Continuously monitor system logs and cellular traffic for irregular memory writes or suspicious patterns, and enforce firmware integrity checks to detect exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android Cellular Modem Allows Remote Privilege Escalation

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android Cellular Modem Enables Privilege Escalation

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Android Cellular Modem Enables Privilege Escalation

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:58:15.559Z

Reserved: 2025-10-23T08:45:55.514Z

Link: CVE-2026-0200

cve-icon Vulnrichment

Updated: 2026-09-15T21:18:22.634Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:15.133

Modified: 2026-09-21T17:20:56.217

Link: CVE-2026-0200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:15:08Z

Weaknesses