Junglewise Threat Intelligence

CVE-2026-0127: Google Pixel Modem out-of-bounds read in cn_NrmmDecoder.cpp

CVE-2026-0127 · Severity: info · CVSS 5.3 · Published 2026-06-16

Technologies: Google Pixel Modem. Vendors: Google.

Executive brief

A vulnerability exists in the modem component of Google Pixel devices. This component handles cellular communications, and a flaw in how it processes certain messages could allow a remote attacker to crash the communication processor. This would result in a loss of cellular connectivity (denial of service) for the user without requiring any interaction from them.

Technical details

An out-of-bounds read vulnerability exists in the 'cn_NrmmDecoder.cpp' file within the 'NrmmMsgCodec::DecodeUPUTransparentContext' function of the Google Pixel modem firmware. The flaw is caused by memory corruption during the decoding of specific network messages. A remote attacker can exploit this over the network without any special privileges or user interaction. Successful exploitation results in a crash of the communication processor, leading to a denial of service (DoS). The issue is addressed in the June 2026 Pixel Security Bulletin with patch levels 2026-06-05 or later.

Affected products

  • Google Pixel Modem Devices with security patch levels before 2026-06-05

Timeline

  • 2026-06-16: advisory: NVD and Google Pixel Bulletin published
  • 2026-06-05: patched: Security patch level date for fix

References

Related threats