Full Breakdown
Google Patches Actively Exploited Pixel Modem Zero-Day (CVE-2026-58704)
By Drooid · · How we work
Core Event
Google disclosed that a high-severity privilege-escalation flaw in the cellular modem of Pixel smartphones, identified as CVE-2026-58704 (CVSS 8.0), was being exploited in the wild. The vulnerability allows a “zero-click” attack: an adversary can bypass permission checks and gain elevated privileges without any user interaction. Google released a security update that resolves the flaw in patch levels dated September 5, 2026 or later.
Background & Context
The modem issue follows a pattern of recent Pixel vulnerabilities. In June 2026, Google patched a separate high-severity Android Framework flaw (CVE-2025-48595, CVSS 8.4) that was also reported as actively exploited. The September update addressed a total of 109 security flaws, including 88 privilege-escalation bugs, 10 information-disclosure issues, nine remote-code-execution defects, and two denial-of-service weaknesses.
Data & Statistics
- CVE-2026-58704: privilege-escalation, remote (proximal/adjacent) escalation, no user interaction required.
- Over 200 vulnerabilities were patched in the September 2026 release, with the modem flaw singled out as “actively exploited in the wild.”
- Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026 and mandated that Federal Civilian Executive Branch agencies apply the fix by September 19, 2026.
Official Statements & Responses
Google confirmed that a “limited” number of Pixel devices had been targeted but did not disclose the identity of the threat actor. A Google spokesperson declined to comment further when approached for details.
Verbatim Quotes
- “Google Pixel devices contain an improper authorization vulnerability in the cellular modem,” — CISA
