Out of Bounds Write in Modem Affects Android Devices
CVE-2026-0120

9.8CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-0120?

A vulnerability exists in the modem component of Android that permits an out of bounds write due to an incorrect bounds check. This flaw enables the possibility of remote code execution without the need for user interaction or additional execution privileges, posing a significant security risk across various Android versions.

Affected Version(s)

Android Android kernel

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.