VYPR
Unrated severityNVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-0154

CVE-2026-0154

Description

A memory corruption vulnerability in the Modem component during SIP REFER request processing could allow remote code execution without user interaction.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A memory corruption vulnerability in the Modem component during SIP REFER request processing could allow remote code execution without user interaction.

Vulnerability

The vulnerability resides in the Modem component of Google Pixel devices. It is triggered by a specifically crafted SIP REFER request, which causes memory corruption and can lead to a modem crash. The issue affects all supported Google devices running a security patch level earlier than 2026-06-05.

Exploitation

An attacker can exploit this vulnerability by sending a malicious SIP REFER request to the target device over the network. No user interaction is required, and the attacker does not need any additional execution privileges beyond the ability to send the crafted request. The memory corruption occurs during processing of the SIP message, potentially leading to code execution.

Impact

Successful exploitation could allow arbitrary code execution within the Modem context. Since the Modem operates with high privileges on the device, this could lead to full compromise of the device, including access to sensitive data, persistent control, or further escalation of privileges.

Mitigation

The fix for CVE-2026-0154 is included in the 2026-06-05 security patch level, as detailed in the Pixel Update Bulletin—June 2026 [1]. All supported Google devices should apply the June 2026 security update to remediate the vulnerability. No workarounds are currently available.

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.