Skip to finding
important · Mobile / Zero-click

A cellular-adjacent attacker can execute code in an affected Pixel modem without user interaction.

Affects

Supported Google Pixel phones and their cellular-modem software.

A crafted modem input triggers a heap-buffer overflow and out-of-bounds write, but the required low-privilege network role and affected modem families are not public.

Detail and 2 sources

The September 2026 Pixel patch level addresses the vulnerability.

Chain to watch
Obtain the required cellular-adjacent position→↓Deliver the undisclosed modem input→↓Trigger the out-of-bounds write and modem-context execution→↓The cellular message and required network role remain unknown.
Unverified chainObtain the underlying fix or a reproduction that identifies the message, network role and affected modem families.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026