DIRAS TAKE
Treat this as high urgency: the IMS flaw allows authentication bypass with no user interaction, meaning an unauthenticated remote attacker could attempt privilege escalation against affected Android kernel deployments.
What is CVE-2026-55366?
Remote attackers can bypass authentication in the Android kernel IP Multimedia Subsystem (IMS) and escalate privileges, potentially gaining full impact on confidentiality, integrity, and availability. CVE-2026-55366 describes this IMS logic error; it affects the Android kernel (IMS component). Exploitation requires no user interaction and reportedly does not require existing execution privileges, but the vendor has not published fixed kernel versions in the provided data.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Android are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Android | Android kernel |
Is CVE-2026-55366 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-55366
- Restrict network exposure of IMS services and block or filter traffic to IMS interfaces from untrusted networks.
- Apply vendor guidance when Google or device vendors publish patches for the Android kernel IMS component.
- Enable and review kernel and IMS-related logs and alerts for unusual authentication or privilege escalation attempts.
- Isolate or remove vulnerable devices from critical networks until a vendor fix is applied.
Frequently asked questions
Is CVE-2026-55366 being actively exploited?
There are no public reports of active exploitation of CVE-2026-55366 as of 2026-09-29.
Which Android versions are affected by CVE-2026-55366?
The advisory data lists the Android kernel (IMS component) as affected; no specific Android release or fixed versions are provided in the supplied facts.
Is there a patch for CVE-2026-55366?
No fixed versions are listed in the provided data; monitor Google and your device vendor for published Android kernel IMS patches.
Does CVE-2026-55366 require authentication?
No—CVE-2026-55366 is described as an authentication bypass in the Android IMS code and does not require user interaction or prior authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-55366
- cve.org/CVERecord?id=CVE-2026-55366
- source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
- All Google CVEs on CVE Radar
- CVEs published in September 2026