Executive brief
A cellular modem firmware component used in Google Pixel devices contains a denial of service vulnerability triggered by improper validation of network input. An attacker within proximal/adjacent network range can remotely crash the modem or cause service interruption without needing special privileges or user interaction, potentially disrupting cellular connectivity and emergency calling capabilities.
Technical details
The vulnerability is a denial of service flaw in the cellular modem firmware caused by improper input validation of network traffic. The attack vector is adjacent/proximal network access—meaning an attacker within wireless range can trigger the issue without authentication or user interaction. Successful exploitation causes a modem crash or malfunction, degrading or eliminating cellular service. The issue is patched in Google Pixel devices at security patch level 2026-09-05 or later, as detailed in the September 2026 Pixel Update Bulletin.
Affected products
- Google Pixel Devices (Cellular Modem Firmware) Pre-2026-09-05 security patch level
Timeline
- 2026-09-15: disclosed
- 2026-09-05: patched: Pixel security patch level 2026-09-05 or later