Description
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

This vulnerability in the Android Modem component allows an attacker to read sensitive data through improper input handling. The flaw results in a remote information disclosure; no additional execution privileges are required and no user interaction is necessary. The weakness is a classic input validation error, identified as CWE‑20.

Affected Systems

Google Android devices that include the Modem subsystem are impacted. Specific affected firmware or build versions have not been disclosed, so all current Android releases may be vulnerable until a patch is issued.

Risk and Exploitability

With a CVSS score of 7.5 the risk is high. Because the flaw can be triggered remotely and does not need user interaction, an attacker could potentially harvest confidential modem data from a victim device. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet the exposure of sensitive data warrants prompt attention.

Generated by OpenCVE AI on September 17, 2026 at 08:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update from Google that addresses the Modem input validation issue.
  • If an update is not yet available, consider disabling or limiting modem functionality or restricting the device’s network connectivity until a patch is released.
  • Monitor device logs for abnormal modem behavior and isolate compromised devices to prevent further data exfiltration.

Generated by OpenCVE AI on September 17, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in Android Modem due to Improper Input Validation

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in Android Modem due to Improper Input Validation

Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:01:26.526Z

Reserved: 2026-06-23T16:25:16.340Z

Link: CVE-2026-57008

cve-icon Vulnrichment

Updated: 2026-09-15T20:16:11.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:30.520

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-57008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T09:00:17Z

Weaknesses
  • CWE-20

    Improper Input Validation