Junglewise Threat Intelligence

CVE-2026-0136: Google Pixel Modem out-of-bounds read causing remote DoS

CVE-2026-0136 · Severity: info · CVSS 7.5 · Published 2026-06-16

Technologies: Google Pixel Modem. Vendors: Google.

Executive brief

A vulnerability exists in the modem component of Google Pixel devices that could allow a remote attacker to crash the device's cellular connectivity. This issue occurs because the modem fails to properly check the size of incoming data, leading to a denial-of-service condition. An exploit could disrupt mobile communications and data services without any interaction from the user.

Technical details

An out-of-bounds read vulnerability exists in the Modem firmware of Google Pixel devices. The flaw is caused by a missing bounds check during the processing of incoming data, which can be triggered remotely. An attacker can exploit this to cause a denial-of-service (DoS) condition, effectively disabling the modem's functionality. The attack requires no special privileges and no user interaction. Google addressed this vulnerability in the June 2026 Pixel Security Bulletin.

Affected products

  • Google Pixel Modem Devices prior to June 2026 patch level

Timeline

  • 2026-06-16: advisory: NVD and Google Pixel Security Bulletin published
  • 2026-06-05: patched: Security patch level date for fix

References

Related threats