Description
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: Yes
Impact: Remote Privilege Escalation via Permission Bypass
Action: Immediate Patch
AI Analysis

Impact

The flaw is a logic error in the Android Cellular Modem code that permits a device to bypass required permission checks. This flaw can be exploited to elevate privileges without additional execution rights, and no user interaction is required. An attacker can leverage this to run code with higher authority than intended. The primary weakness is a permission violation leading to privilege escalation.

Affected Systems

The issue affects Google Android devices that implement the Cellular Modem component. No specific product versions were listed, so any device using the affected code may be vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 8.8 signals high severity. The EPSS score is reported as less than 1%, suggesting current exploitation probability is low, but the issue is listed in the CISA KEV catalog, indicating confidence that it is materially exploitable. The likely attack vector is remote or proximal/adjacent, such as through the cellular network or from a nearby device, with no user interaction required. The exploit path relies on the logic error that circumvents permission validation within the modem driver.

Generated by OpenCVE AI on September 20, 2026 at 13:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Android security update from Google that addresses the Cellular Modem logic error
  • If an update is not immediately available, limit the device’s cellular connectivity and disable unused modem services as a temporary defense
  • Continuously monitor Google Android security bulletins for a formal patch or advisory and verify deployment after release

Generated by OpenCVE AI on September 20, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Cellular Modem Permission Bypass on Android

Thu, 17 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Android Cellular Modem Permission Bypass Leading to Privilege Escalation

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-09-16T00:00:00+00:00', 'dueDate': '2026-09-19T00:00:00+00:00'}


Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Android Cellular Modem Permission Bypass Leading to Privilege Escalation

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-693
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-17T03:55:53.112Z

Reserved: 2026-07-02T05:38:24.955Z

Link: CVE-2026-58704

cve-icon Vulnrichment

Updated: 2026-09-15T18:51:46.315Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T19:17:32.297

Modified: 2026-09-17T04:17:54.930

Link: CVE-2026-58704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:30:17Z

Weaknesses