Impact
A flaw exists in the Cellular Modem component of Android, where untrusted data is not properly validated before processing. This improper input handling can cause the modem to crash, resulting in a loss of network connectivity and overall device unavailability. The weakness is identified by CWE‑20, indicating a lack of input validation. If successfully triggered, the flaw leads to a remote denial of service without the need for user interaction or elevated privileges.
Affected Systems
The devices affected are those that run Google’s Android OS with the Pixel platform modem code. No specific version range is listed, so all currently shipped Android devices that include the problematic modem implementation are potentially impacted. The exact devices are inferred to be officially released.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. It is inferred that the attacker can deliver malicious payloads over an external network to exploit the flaw, thanks to the remote nature local access. Because the EPSS score is < 1%, the actual exploitation probability is very low, but the absence of local privileges and the remote delivery path highlight that the vulnerability could still be targeted. The vulnerability is not present in the CISA KEV catalog.
OpenCVE Enrichment