CVE-2026-58704
Published Sep 15, 2026
Last updated 7 hours ago
- Description
- In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Source
- dsap-vuln-management@google.com
- NVD status
- Analyzed
- Products
- android
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Google Pixel Improper Authorization Vulnerability
- Exploit added on
- Sep 16, 2026
- Exploit action due
- Sep 19, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-285
- Hype score
- Not currently trending
Google Pixel Vulnerability Exploited: CVE-2026-58704 Enables Zero-Click Privilege Escalation(Google Pixelの脆弱性CVE-2026-58704、ゼロクリック攻撃で悪用) #SecurityOnline (Sep 16) https://t.co/SkQ8ULBvGZ
@foxbook
17 Sept 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに1件と2件の脆弱性を追加。 - CVE-2026-58704 (Google Pixel) - CVE-2026-76460 (Cisco ISE) - CVE-2026-87886 (Acronis Backup) 対処期限は3日後の
@__kokumoto
16 Sept 2026
552 Impressions
0 Retweets
4 Likes
0 Bookmarks
1 Reply
0 Quotes
Google confirmed a Pixel cellular modem vulnerability was exploited in targeted attacks. - CVE-2026-58704 is a permission bypass caused by a logic error in the modem - Patched in the September 2026 Pixel security update - That update fixes more than 200 security issues in total
@sammygurus
16 Sept 2026
362 Impressions
1 Retweet
2 Likes
0 Bookmarks
3 Replies
0 Quotes
Google Pixel Cellular Modem Authorization Bypass (CVE-2026-58704) A high-severity logic flaw in Google Pixel cellular modem firmware (CVE-2026-58704) allows adjacent attackers to bypass permission checks. Full write-up → link in bio #cybersecurity #infosec #cve #kev #google h
@HotaSamit
16 Sept 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-58704: CISA KEV Flags Actively Exploited Google Pixel Improper Authori… "CISA has added CVE-2026-58704, a Google Pixel improper authorization vulnerability, to the…" 🔗 https://t.co/d5zXlC4s08 #CyberSecurity #ThreatIntel #cve #zeroday
@SecurityAr58409
16 Sept 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-58704: Google Pixel Cellular Modem Vulnerability Actively Exploited — … "On 2026-09-16, CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities (KEV)…" 🔗 https://t.co/ulKppSXhPM #CyberSecurity #ThreatIntel #cve202658704 #critical
@SecurityAr58409
16 Sept 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New alert for Pixel owners: CVE-2026-58704 is a zero-day modem bug enabling privilege escalation from nearby networks, no clicks needed. Google’s September 2026 patch (2026-09-05 level) fixes it—110 vulnerabilities addressed in total, but this one stands out. Update your devi
@dailytechonx
16 Sept 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The harder part is what stays unpublished: which Pixel models were exposed, which firmware, how long the bug was live before it was found, and whether the exploit was bought, built in-house, or handed to a government... Google confirmed CVE-2026-58704 was exploited in targeted
@0J0BIT
16 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. #infosec #googlepixel #CVE #microsoft https://t.co/e3jssmKmvu
@TheThreatForge
16 Sept 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/09/16 🚨 1. Google patches an exploited Pixel zero-day September Pixel updates cover 110 flaws, including CVE-2026-58704 — a modem privilege-escalation bug Google says is already used in limited, targeted attacks. Install the 2026-09-05 patch le
@FrontieraTechIT
16 Sept 2026
123 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Google Patches Actively Exploited Pixel Modem Zero-Day CVE-2026-58704 Google releases September 2026 security updates for Pixel devices, patching active zero-day CVE-2026-58704 alongside 109… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #goog
@HotaSamit
16 Sept 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Google: actively exploited Pixel zero-day CVE-2026-58704 in September modem patches (110 flaws total). Limited targeted attacks. Adjacent priv-esc, no user click needed. Patch Pixel fleets to 2026-09-05 now. #CyberSecurity #Android #CVE Link: https://t.co/avoN9PpXIb
@Orion84x
16 Sept 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]