CVE-2026-50207: Local Modem Manipulation via Binder Interfaces
Published Jun 4, 2026
·Updated
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
Affected Software
3 affected components
Google Android
All of the following
Acer Connect M6e 5g Firmware<=m6e_ai_1.00.000019
Acer Connect M6e 5g
Event History
Jun 4, 2026
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-50207?
CVE-2026-50207 has a severity rating of 8.5, categorized as high risk.
2
What vulnerabilities are present in CVE-2026-50207?
CVE-2026-50207 allows for local manipulation of modem functionalities due to unverified pass-through AT commands.
3
How do I fix CVE-2026-50207?
To mitigate CVE-2026-50207, update to the latest Google Android version that addresses this vulnerability.
4
What systems are affected by CVE-2026-50207?
CVE-2026-50207 specifically affects Google Android devices that utilize the Binder interface.
5
What are the potential impacts of CVE-2026-50207?
Exploitation of CVE-2026-50207 could lead to unauthorized access to baseband files and disabling of cellular connectivity.