Junglewise Threat Intelligence

CVE-2026-0200: Google Pixel Cellular Modem heap buffer overflow

CVE-2026-0200 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

A cellular modem component used in Google Pixel devices contains a heap buffer overflow vulnerability that allows remote attackers to escalate privileges without user interaction. This could give an attacker complete control over the device through network-based exploitation of the cellular subsystem.

Technical details

CVE-2026-0200 is a heap buffer overflow resulting in an out-of-bounds write in the Cellular Modem component of Google Pixel devices. The vulnerability is remotely exploitable with no additional execution privileges required, and user interaction is not needed for exploitation. An attacker can leverage this to achieve privilege escalation and potentially execute arbitrary code on the device. The issue was patched as part of the September 2026 Android security patch level (2026-09-05).

Affected products

  • Google Pixel Versions prior to security patch level 2026-09-05

Timeline

  • 2026-09-15: disclosed: Published in Google Pixel Update Bulletin—September 2026
  • 2026-09-05: patched: Patched in Android security patch level 2026-09-05

References

Related threats