CVE-2026-0154
Description
A memory corruption vulnerability in the Modem component during SIP REFER request processing could allow remote code execution without user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A memory corruption vulnerability in the Modem component during SIP REFER request processing could allow remote code execution without user interaction.
Vulnerability
The vulnerability resides in the Modem component of Google Pixel devices. It is triggered by a specifically crafted SIP REFER request, which causes memory corruption and can lead to a modem crash. The issue affects all supported Google devices running a security patch level earlier than 2026-06-05.
Exploitation
An attacker can exploit this vulnerability by sending a malicious SIP REFER request to the target device over the network. No user interaction is required, and the attacker does not need any additional execution privileges beyond the ability to send the crafted request. The memory corruption occurs during processing of the SIP message, potentially leading to code execution.
Impact
Successful exploitation could allow arbitrary code execution within the Modem context. Since the Modem operates with high privileges on the device, this could lead to full compromise of the device, including access to sensitive data, persistent control, or further escalation of privileges.
Mitigation
The fix for CVE-2026-0154 is included in the 2026-06-05 security patch level, as detailed in the Pixel Update Bulletin—June 2026 [1]. All supported Google devices should apply the June 2026 security update to remediate the vulnerability. No workarounds are currently available.
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.