CVE-2026-0135: In Modem, there is a possible out of bounds read due to a missing bounds check
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An out-of-bounds read vulnerability exists in the Android kernel Modem component due to a missing bounds check. The flaw is reachable locally by any low-privilege process without requiring user interaction, as described by the CVSS vector. Successful exploitation gives an attacker full read, write, and execution control over the affected system, enabling remote code execution at the same privilege level. No fix version has been published yet; HarborGuard tracks the advisory and will surface a patched-image rebuild the moment upstream releases one.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built Android kernel or Modem images in CI pipelines and registries. Any image carrying an affected kernel version is flagged automatically.
AvailableTriage capability is available using the CVSS v3.1 score of 7.8 (HIGH), weighted against each customer organization's compliance policy to determine breach thresholds and escalation priority. Findings are routed to the appropriate team inbox within each customer environment based on configured ownership rules.
AvailableBecause no upstream fix version has been published for CVE-2026-0135, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment a fix is released upstream. In the interim, customers can apply compensating controls through HarborGuard's policy engine, such as network-policy isolation for workloads running affected images.
Pending upstreamExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host; no over-the-network path to the vulnerable component is required (AV:L).
- AuthenticationRequired
Any low-privilege account on the system is sufficient to trigger the vulnerability; no elevated or administrative credentials are needed (PR:L).
- Victim interactionNot required
No user action such as opening a file or clicking a link is required for exploitation (UI:N).
- Attack complexityDetail
The exploit is reliable and condition-free, with no race conditions or specific memory-layout requirements needed (AC:L).
Blast Radius
- A successful attacker reads arbitrary memory regions from the Modem component, exposing sensitive data held in kernel address space.
- The attacker writes to out-of-bounds memory, allowing modification of kernel data structures or persisted state.
- Full code execution is achievable within the compromised process context, giving the attacker control over the affected system's modem subsystem.
- All three pillars of confidentiality, integrity, and availability are rated HIGH, meaning the attacker can crash the modem service entirely in addition to reading and modifying data.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-0135 is active across customer environments, matching against any image that packages an affected Android kernel build. Because no upstream fix exists at this time, HarborGuard monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild and, for customers with auto-remediation enabled, open a regression-tested PR against affected workloads as soon as upstream publishes a fix. While waiting for a patch, customers can use HarborGuard's policy engine to apply compensating controls: isolating affected workloads via Kubernetes network policy, restricting which images are permitted to run in production namespaces, or flagging the CVE as an accepted risk with a mandatory review date. The advisory status is reflected in real time on each customer's dashboard.
- Google / AndroidAndroid kernel
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H