Modem Driver Flaw: Android Users Urged to Install September Patch

Users of smartphones from Google, Samsung, Xiaomi, and Motorola should promptly check their system settings for pending updates. Several vulnerabilities across the devices potentially enable unauthorized data access. Particularly concerning is a zero-day flaw in the cellular modem that can be exploited without any user interaction.

Critical Zero-Day Flaw in Modem Driver

A high-severity vulnerability has been discovered in the cellular modem driver on Google Pixel devices. According to security firm Lookout, it stems from a logic bug that bypasses permission checks, allowing attackers to escalate privileges to the baseband or modem level. The exploit requires no user interaction whatsoever. Google is delivering a fix via the security patch level dated September 5, 2026, or newer, following reports that Google addressed the zero-click modem vulnerability for Pixel smartphones. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the issue to its Known Exploited Vulnerabilities catalog.

Comprehensive Patches for Xiaomi and Samsung

Other manufacturers are also rolling out security updates to address critical vulnerabilities:

  • Xiaomi: With its September update, the manufacturer is delivering 95 fixes for the Android system alongside 85 patches for hardware components from vendors such as Qualcomm, MediaTek, Arm, Imagination, and Unisoc. The most severe flaw allowed remote code execution without user interaction. The update is rolling out as part of HyperOS 4 and impacts models including the Xiaomi 15, Xiaomi 15 Ultra, Xiaomi 17T, Xiaomi 17T Pro (including EEA versions for the European Economic Area), Xiaomi MIX FLIP 2, as well as POCO models (F7 Pro, F7 Ultra, F9 Ultra) and the Redmi series (K80, K80 Pro, K100 Pro Max).
  • Samsung: A hotfix containing 89 security enhancements has been deployed for Beta 2 of One UI 9 on the Galaxy S23, initially rolling out primarily in South Korea. At the same time, the global rollout of the stable One UI 9.0 version is underway, beginning with the Galaxy S26 in South Korea and the US; older models such as the Galaxy S23 and other eligible devices are expected to follow gradually by the end of the year. In India, a beta is also being tested for the Galaxy A07 5G.
  • Motorola: Patches have also been announced or are currently rolling out for the brand’s devices to prevent unauthorized access.
See also  Opera for Android: New Built-in eSIM Feature Offers Travel Data

What Smartphone Owners Should Do Now

Given the severity of these flaws—particularly the risk of zero-click remote code execution or kernel tampering—owners of affected smartphones should not wait for automatic notifications. Manually check for available updates in the system settings under the software or system update menu.

Pixel devices should have at least the September 5, 2026, security patch level installed. Because updates from manufacturers like Samsung and Xiaomi are often deployed in phased regional rollouts, there may still be delays depending on the model and country before the patch is ready to download on every device.

Sources: Borncity.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top