Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Trending:
Galaxy S26•Pixel 10•Android 16•Nothing OS•Gemini AI•Smartwatches•Tech Deals•Latest Reviews•How-to Guides
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/Google describes a 0-click modem problem in the Pixel 6: encourages people to turn off 2G
News
google

Google describes a 0-click modem problem in the Pixel 6: encourages people to turn off 2G

Robert Haba
Aug 13, 20235 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
2g
0%
Share on XFacebookBluesky
Follow on Google
Advertisement
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Key Takeaways

Automated Editorial Synthesis
AI Overview
  • A significant 0-click vulnerability in the Pixel 6 modem stack was identified by Google's Android Red Team and has since been patched.
  • This vulnerability allows a skilled attacker to take control of a target's Android device by making a call to the victim.
  • The aforementioned bugs were first found in 2021 by Android Red Team members.

A significant 0-click vulnerability in the Pixel 6 modem stack was identified by Google’s Android Red Team and has since been patched. This vulnerability allows a skilled attacker to take control of a target’s Android device by making a call to the victim.

Four members of Google’s Android Red Team demonstrated how two Pixel modem vulnerabilities (CVE-2022-20170, CVE-2022-20405) could be combined to first hijack a targeted Pixel’s cellular modem communication to the second-generation (2G) wireless standard with the aid of a cheap $1,000 home-made cellphone base station during the Wednesday Black Hat session.

Advertisement

The aforementioned bugs were first found in 2021 by Android Red Team members. With a CVSS score of 9.8, both modem flaws are now classified as critical. The over-the-air remote code execution bug, designated CVE-2022-20170, was addressed in June 2022. An elevation of privilege (EoP) weakness was discovered in the second vulnerability, tracked as CVE-2022-20405, and it was fixed in August 2022. The EoP bug was deemed to be of moderate severity when it was initially discovered in an Android security bulletin.

If the attack is successful, the enemy will be able to wirelessly execute remote code that is running in the Pixel modem’s privileged context. According to experts, an attacker would then be able to conduct out assaults against the handset, such as launching a DoS attack, performing SMS/RSC (text message) sniffing and spoofing, MFA compromise, and enabling a hacker to switch to the device’s main operating system kernel.

Google claimed that it was not aware of the issues being used in the wild and that internal Alphabet procedures were to blame for the delay in disclosing the technical CVE information.

Advertisement

2G is obsolete

The Android Red Team at Black Hat includes Xuan Xing, Eugene Rodionov, Xiling Gong, and Farzan Karimi to demonstrate the assault (see image). Exploiting flaws in the Android Pixel’s cellular data connection to 2G networks is the initial attack vector.

You May Also Like
Recommended
1

Huawei Kirin 9050 Pro chipset: full specs and what’s new

kirin 9050
2

The 5 biggest phone launches to watch in September 2026

semptember 2026 phones
3

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

The goal of this attack, according to Karimi, is to downgrade mobile devices to 2G.

The majority of modern cellular modems operate on 4G or 5G frequency bands. Yet, the majority of cellular data modem chipsets continue to support 2G and other dated wireless frequencies. For uncommon use scenarios including outdated wireless network geography, devices cycling down to save handset power consumption, and phones going to international markets where legacy 2G cellular networks are more prevalent, legacy support is required.

Weak encryption between towers and devices is one of the security vulnerabilities with 2G, which attackers may (and have) easily hacked in order to intercept conversations or text messages. Even current phones, according to researchers, occasionally transition to 2G to handle signal congestion, roaming, and network switching better.

Advertisement

The Android Red Team went above and beyond the examples of hackers and government enforcement utilizing fake base stations dubbed ISMI catchers (international mobile subscriber identity) or surveillance tools like Stingray to collect phone ID data, geolocation data, and content. They demonstrated how a vulnerable Pixel phone could be controlled remotely via a $1,000 home-built base station in addition to being used to collect data.

Breaking down the attack

The Android Red Team went above and beyond the examples of hackers and government enforcement utilizing fake base stations dubbed ISMI catchers (international mobile subscriber identity) or surveillance tools like Stingray to collect phone ID data, geolocation data, and content. They demonstrated how a vulnerable Pixel phone could be controlled remotely via a $1,000 home-built base station in addition to being used to collect data.

“When a victim comes in proximity (a range of less than 5 miles) of the malicious base station it will connect to it,” said Karimi. “That allows the adversary to send the exploit payload and establish a foothold on the victim’s modem.”

In more precise terms, the RCE issue is an out-of-band (OOB) write error that happens during the decoding of OTA packets from 2G GSM connection. According to researchers, the EoP fault is caused by an error in the Pixel 6’s modem code, which renders memory space RWX (also known as the read (r), write (w), and execute (x) permissions) and available via signal processing instructions.

 “The attacker fully controls up to 255 bytes written into 1-byte buffer in the heap,” researchers said. “CVE-2022-20170 enables us to overwrite heap header of the next adjacent chunk with fully controlled data.”

According to Google, the exploit technique allowed them to “corrupt nearby heap items and put a small amount of controlled bytes in the heap.” Uncertainty surrounds whether any of those items had an effect on the memory management unit (MMU) of the modem, which is essential to the next phase of the attack.

Researchers were able to execute 80 bytes of malicious shellcode via the modem’s (MMU) misconfiguration vulnerability (CVE-2022-20405), giving the attacker access to the affected device.

Google tip: Disable 2G

disable 2g

The 2G-attack method actually poses a threat. There have been reports of temporary 2G base stations popping up close to the hotels Paris Las Vegas and Caesars Palace during what is known as Hacker Summer Camp in Las Vegas, which features three security conferences: BSides, Black Hat, and DEF CON. Participants in DEF CON are renowned for having a habit of exposing cybersecurity experts who expose their digital equipment to a cyberattack.

Researchers strongly advised Black Hat attendees to turn off 2G support on their phones. To turn off 2G capability, simply search for 2G in Settings on an Android device.

In related news, Google announced Tuesday a suite of Android 14 advanced cellular security mitigations for enterprises.

“Android 14 introduces support for IT administrators to disable 2G support in their managed device fleet. Android 14 also introduces a feature that disables support for null-ciphered cellular connectivity,” according to a Google Security Blog writeup.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#2g#4g#androidgoogle#modem#security#update
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
Google Pixel Watch 4

Google Pixel Watch 4

4.8
396.00$499.99-21%
Buy on Amazon
💎Best Android Device
Samsung Galaxy S26 Ultra

Samsung Galaxy S26 Ultra

4.9
$1,212.85$1,499.99-19%
Buy on Amazon
👑A good choice
Apple iPhone 17 Pro

Apple iPhone 17 Pro

4.8
$1,012.97$1,099.00-8%
Buy on Amazon
Samsung Galaxy Watch 8

Samsung Galaxy Watch 8

4.9
$289.99$349.99-17%
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Advertisement

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Advertisement

Latest Stories

01

Honor MagicOS 11 to debut with hidden Power Saving Suggestions feature

02

Galaxy Watch 4 and Watch 4 Classic reach end of software support

03

GrapheneOS merges Secure Paste to limit clipboard access

04

Android 17 quietly blocks apps from detecting Developer Mode status

Advertisement
Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Advertisement
Advertisement
Recommended stories

Continue reading

More from this category →
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
semptember 2026 phones
NewsSep 8, 2026

The 5 biggest phone launches to watch in September 2026

September is usually iPhone season, but this year several Android brands are packing their very best hardware into the same four-week stretch, aiming to steal some of the spotlight. More than 20 phones are expected to launch this month alone, and here's a rundown of five of the biggest phone launches on the calendar for […]

By Luiza Mosneagu
NewsSep 4, 2026

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

Google's Scam Detection feature could be coming to Xiaomi phones next, according to a new APK teardown by Android Authority. The AI-powered scam-call warning tool debuted first on Pixel devices, has since expanded to Samsung's Galaxy S26 series, and has shown signs of heading to vivo phones as well, and Android Authority now says it's […]

By Robert Haba
android-trojan
NewsSep 4, 2026

New StreamRat Android banking trojan spreads via fake streaming ads

Cybersecurity researchers at ThreatFabric have disclosed a new Android banking trojan called StreamRat that was pushed to Spanish-speaking users through a fake television-streaming campaign on Meta and can hand its operators near-complete control of an infected device. According to ThreatFabric, the campaign's advertising focused on Spain and reached an estimated 570,950 Meta accounts in the […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.