Junglewise Threat Intelligence

CVE-2026-55306: Google Pixel cellular modem denial of service

CVE-2026-55306 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

The cellular modem in Google Pixel devices contains an improper input validation flaw that allows remote attackers to trigger a denial-of-service condition without requiring special privileges or user interaction. A successful attack would disrupt cellular connectivity on affected phones, potentially making them unable to send calls, texts, or use mobile data until the device is restarted.

Technical details

The vulnerability is a denial-of-service issue in the cellular modem component caused by improper input validation. An attacker on the network can send a specially crafted input to the modem to trigger the flaw, resulting in a service outage. No special execution privileges are required, and user interaction is not needed for exploitation. The attack vector is network-based. Google has patched this issue and it is addressed in the 2026-09-05 security patch level for all supported Pixel devices.

Affected products

  • Google Pixel All supported versions prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched

References

Related threats