Description
In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via out-of-bounds write in the Cellular Modem
Action: Patch Immediately
AI Analysis

Impact

In Android cellular modem firmware, a heap buffer overflow can trigger an out-of-bounds write, enabling remote code execution without any user interaction to exploit, making it a serious risk for affected devices.

Affected Systems

Devices running Android information is not supplied in the advisory, so all current Android releases that include the vulnerable modem firmware are potentially impacted.

Risk and Exploitability

With a CVSS score of 8 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the overflow from a proximity or adjacent context, as the description indicates a “proximity/adjacent” code execution scenario. Because no privileges are required and user interaction is unnecessary, the risk is significant if the exploit succeeds.

Generated by OpenCVE AI on September 17, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest update in the 2026-09-01 Android security bulletin.
  • If the device cannot be patched, disable the cellular modem or remove it from active operation to eliminate the vulnerable code path.
  • Log and review system activity for unexpected memory access attempts, is detected.

Generated by OpenCVE AI on September 17, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Cellular Modem Leading to Remote Code Execution

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in Cellular Modem Leading to Remote Code Execution

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T03:57:45.951Z

Reserved: 2026-06-23T16:16:45.565Z

Link: CVE-2026-56967

cve-icon Vulnrichment

Updated: 2026-09-15T20:39:08.002Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:28.950

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-56967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T10:15:08Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow