Junglewise Threat Intelligence

CVE-2026-0159: Google Pixel Cellular Modem out-of-bounds write

CVE-2026-0159 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

A cellular modem in Google Pixel devices contains a missing bounds check that allows an attacker to write data beyond allocated memory. This vulnerability can be exploited remotely to execute arbitrary code on the device with no user interaction required, potentially giving an attacker full control of the phone's communication and baseband functionality.

Technical details

This vulnerability is an out-of-bounds write in the cellular modem caused by a missing bounds check during memory operations. The affected component is the modem subsystem, which handles cellular communication on Pixel devices. The vulnerability is remotely exploitable over the network (cellular interface) with no authentication or user interaction required, allowing unauthenticated attackers to trigger the out-of-bounds write and achieve remote code execution within the modem's execution context. Google addressed this issue in Pixel devices with the September 5, 2026 security patch level.

Affected products

  • Google Pixel All supported Pixel devices prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed: Published in Google Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Addressed in Pixel security patch level 2026-09-05

References

Related threats