HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-0135Published Modified CNA Google_Devices

CVE-2026-0135: In Modem, there is a possible out of bounds read due to a missing bounds check

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An out-of-bounds read vulnerability exists in the Android kernel Modem component due to a missing bounds check. The flaw is reachable locally by any low-privilege process without requiring user interaction, as described by the CVSS vector. Successful exploitation gives an attacker full read, write, and execution control over the affected system, enabling remote code execution at the same privilege level. No fix version has been published yet; HarborGuard tracks the advisory and will surface a patched-image rebuild the moment upstream releases one.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built Android kernel or Modem images in CI pipelines and registries. Any image carrying an affected kernel version is flagged automatically.

Available
Triage

Triage capability is available using the CVSS v3.1 score of 7.8 (HIGH), weighted against each customer organization's compliance policy to determine breach thresholds and escalation priority. Findings are routed to the appropriate team inbox within each customer environment based on configured ownership rules.

Available
Patch

Because no upstream fix version has been published for CVE-2026-0135, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment a fix is released upstream. In the interim, customers can apply compensating controls through HarborGuard's policy engine, such as network-policy isolation for workloads running affected images.

Pending upstream

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; no over-the-network path to the vulnerable component is required (AV:L).

  • AuthenticationRequired

    Any low-privilege account on the system is sufficient to trigger the vulnerability; no elevated or administrative credentials are needed (PR:L).

  • Victim interactionNot required

    No user action such as opening a file or clicking a link is required for exploitation (UI:N).

  • Attack complexityDetail

    The exploit is reliable and condition-free, with no race conditions or specific memory-layout requirements needed (AC:L).

Blast Radius

  • A successful attacker reads arbitrary memory regions from the Modem component, exposing sensitive data held in kernel address space.
  • The attacker writes to out-of-bounds memory, allowing modification of kernel data structures or persisted state.
  • Full code execution is achievable within the compromised process context, giving the attacker control over the affected system's modem subsystem.
  • All three pillars of confidentiality, integrity, and availability are rated HIGH, meaning the attacker can crash the modem service entirely in addition to reading and modifying data.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-0135 is active across customer environments, matching against any image that packages an affected Android kernel build. Because no upstream fix exists at this time, HarborGuard monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild and, for customers with auto-remediation enabled, open a regression-tested PR against affected workloads as soon as upstream publishes a fix. While waiting for a patch, customers can use HarborGuard's policy engine to apply compensating controls: isolating affected workloads via Kubernetes network policy, restricting which images are permitted to run in production namespaces, or flagging the CVE as an accepted risk with a mandatory review date. The advisory status is reflected in real time on each customer's dashboard.

See how HarborGuard automates this
Affected packages
  • Google / Android
    Android kernel
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H