Google Pixel Cellular Modem Improper Authorization
Improper authorization in Google Pixel's cellular modem lets a nearby attacker bypass permission checks and escalate privileges without user interaction. CISA KEV, due 2026-09-19.
- Vendor
- Product
- Pixel
- CVSS
- 8.8
- EPSS (exploit probability)
- 0.6%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-58704 is an improper authorization flaw in the cellular modem firmware on Google Pixel devices. A logic error allows an attacker in radio adjacency to bypass permission checks and escalate privileges on the device. No user interaction is needed.
Google disclosed the vulnerability as part of its September 2026 Pixel security bulletin on September 15, 2026. CISA added it to the Known Exploited Vulnerabilities catalog on September 16, 2026, with a remediation deadline of September 19 under BOD 26-04.
Affected products: Supported Google Pixel devices. Consult the Pixel update bulletin for the full device list.
Patch: Apply the September 2026 Pixel security patch level via Settings > Security & privacy > System & updates.
The attack vector is adjacent (proximal/adjacent network or radio environment), not the open internet. Confirmed exploitation in the wild as of the KEV addition date.