Junglewise Threat Intelligence

CVE-2026-0154: Google Pixel Modem memory corruption in SIP REFER request

CVE-2026-0154 · Severity: info · CVSS 9.8 · Published 2026-06-16

Technologies: Google Pixel Modem. Vendors: Google.

Executive brief

A vulnerability in the modem firmware of Google Pixel devices could allow an attacker to remotely crash the modem or execute unauthorized code. This occurs when the device processes a specific type of network request used in internet-based calling (SIP REFER). An exploit could lead to a total loss of device communication or allow an attacker to gain control over the modem without any interaction from the user.

Technical details

A memory corruption vulnerability exists in the Modem component of Google Pixel devices. The flaw is triggered during the processing of a SIP REFER request, a standard method used in Session Initiation Protocol (SIP) for call transfer. An unauthenticated remote attacker can exploit this by sending a specially crafted SIP packet over the network, leading to a modem crash or remote code execution (RCE) within the modem's execution environment. No user interaction or special privileges are required for exploitation. Google addressed this in the June 2026 Pixel Security Bulletin; users should update to patch level 2026-06-05 or later.

Affected products

  • Google Pixel Modem Devices prior to June 2026 patch level

Timeline

  • 2026-06-16: disclosed: Vulnerability disclosed in Google Pixel Update Bulletin
  • 2026-06-05: patched: Security patch level released to address the issue

References

Related threats