---
id: CVE-2026-55306
title: >-
  In Cellular Modem, there is a possible denial of service due to improper input
  validation
summary: >-
  In Cellular Modem, there is a possible denial of service due to improper input
  validation. This could lead to remote denial of service with no additional
  execution privileges needed. User interaction is not needed for exploitation.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: google
product: android
affected:
  - android
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:20:36.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55306'
references:
  - url: 'https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01'
    label: dsap-vuln-management@google.com
tags:
  - nvd
  - cve.org
epss: 0.00268
epssPercentile: 0.19184
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T15:54:52.950528Z'
ingestedAt: '2026-09-15T18:41:59.172Z'
---

## Overview

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
