CVE-2026-58704

Published Sep 15, 2026

Last updated 7 hours ago

Overview

Description
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
dsap-vuln-management@google.com
NVD status
Analyzed
Products
android

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Google Pixel Improper Authorization Vulnerability
Exploit added on
Sep 16, 2026
Exploit action due
Sep 19, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-285

Social media

Hype score
Not currently trending
  1. Google Pixel Vulnerability Exploited: CVE-2026-58704 Enables Zero-Click Privilege Escalation(Google Pixelの脆弱性CVE-2026-58704、ゼロクリック攻撃で悪用) #SecurityOnline (Sep 16) https://t.co/SkQ8ULBvGZ

    @foxbook

    17 Sept 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに1件と2件の脆弱性を追加。 - CVE-2026-58704 (Google Pixel) - CVE-2026-76460 (Cisco ISE) - CVE-2026-87886 (Acronis Backup) 対処期限は3日後の

    @__kokumoto

    16 Sept 2026

    552 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Google confirmed a Pixel cellular modem vulnerability was exploited in targeted attacks. - CVE-2026-58704 is a permission bypass caused by a logic error in the modem - Patched in the September 2026 Pixel security update - That update fixes more than 200 security issues in total

    @sammygurus

    16 Sept 2026

    362 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    3 Replies

    0 Quotes

  4. Google Pixel Cellular Modem Authorization Bypass (CVE-2026-58704) A high-severity logic flaw in Google Pixel cellular modem firmware (CVE-2026-58704) allows adjacent attackers to bypass permission checks. Full write-up → link in bio #cybersecurity #infosec #cve #kev #google h

    @HotaSamit

    16 Sept 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🔒 #CyberSecurity CVE-2026-58704: CISA KEV Flags Actively Exploited Google Pixel Improper Authori… "CISA has added CVE-2026-58704, a Google Pixel improper authorization vulnerability, to the…" 🔗 https://t.co/d5zXlC4s08 #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    16 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🔒 #CyberSecurity CVE-2026-58704: Google Pixel Cellular Modem Vulnerability Actively Exploited — … "On 2026-09-16, CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/ulKppSXhPM #CyberSecurity #ThreatIntel #cve202658704 #critical

    @SecurityAr58409

    16 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. New alert for Pixel owners: CVE-2026-58704 is a zero-day modem bug enabling privilege escalation from nearby networks, no clicks needed. Google’s September 2026 patch (2026-09-05 level) fixes it—110 vulnerabilities addressed in total, but this one stands out. Update your devi

    @dailytechonx

    16 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. The harder part is what stays unpublished: which Pixel models were exposed, which firmware, how long the bug was live before it was found, and whether the exploit was bought, built in-house, or handed to a government... Google confirmed CVE-2026-58704 was exploited in targeted

    @0J0BIT

    16 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. #infosec #googlepixel #CVE #microsoft https://t.co/e3jssmKmvu

    @TheThreatForge

    16 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ CYBER BULLETIN | 2026/09/16 🚨 1. Google patches an exploited Pixel zero-day September Pixel updates cover 110 flaws, including CVE-2026-58704 — a modem privilege-escalation bug Google says is already used in limited, targeted attacks. Install the 2026-09-05 patch le

    @FrontieraTechIT

    16 Sept 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Google Patches Actively Exploited Pixel Modem Zero-Day CVE-2026-58704 Google releases September 2026 security updates for Pixel devices, patching active zero-day CVE-2026-58704 alongside 109… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #goog

    @HotaSamit

    16 Sept 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Google: actively exploited Pixel zero-day CVE-2026-58704 in September modem patches (110 flaws total). Limited targeted attacks. Adjacent priv-esc, no user click needed. Patch Pixel fleets to 2026-09-05 now. #CyberSecurity #Android #CVE Link: https://t.co/avoN9PpXIb

    @Orion84x

    16 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations