Junglewise Threat Intelligence

CVE-2026-56975: Google Cellular Modem denial of service via improper input validation

CVE-2026-56975 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

A cellular modem firmware component used in Google Pixel devices contains a denial of service vulnerability triggered by improper validation of network input. An attacker within proximal/adjacent network range can remotely crash the modem or cause service interruption without needing special privileges or user interaction, potentially disrupting cellular connectivity and emergency calling capabilities.

Technical details

The vulnerability is a denial of service flaw in the cellular modem firmware caused by improper input validation of network traffic. The attack vector is adjacent/proximal network access—meaning an attacker within wireless range can trigger the issue without authentication or user interaction. Successful exploitation causes a modem crash or malfunction, degrading or eliminating cellular service. The issue is patched in Google Pixel devices at security patch level 2026-09-05 or later, as detailed in the September 2026 Pixel Update Bulletin.

Affected products

  • Google Pixel Devices (Cellular Modem Firmware) Pre-2026-09-05 security patch level

Timeline

  • 2026-09-15: disclosed
  • 2026-09-05: patched: Pixel security patch level 2026-09-05 or later

References

Related threats