CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities catalog on 2026-09-16, citing an improper authorization flaw in the Google Pixel cellular modem that allows privilege escalation from an adjacent network position.
What Is It
A logic error in the Pixel cellular modem code permits a permission bypass. Per the NVD record, the flaw "could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed," and user interaction is not required. CISA tracks it as the "Google Pixel Improper Authorization Vulnerability," mapped to CWE-693 (Protection Mechanism Failure) and CWE-285 (Improper Authorization).
It carries a CVSS 3.1 base score of 8.8 (HIGH), vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, adjacent-network attack vector, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
CISA adds a CVE to KEV on the basis of evidence of exploitation, and its SSVC decision points for this entry record exploitation as active, technical impact as total, and automatable as no. On CISA's assessment, then, exploitation is occurring, a successful attack yields full control of the affected component, and the flaw is not amenable to scalable worm-like automation. The underlying exploitation evidence has not been published, so the scope, targeting, and volume of any activity are not publicly characterized.
Because the attack vector is adjacent rather than fully remote, an attacker needs radio proximity to the target device. That is a meaningful constraint, but a low bar against a device that requires no user interaction to compromise. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
Google Pixel devices, in the cellular modem component. The NVD configuration matches cpe:2.3:o:google:android:-:*:*:*:*:*:*:*, with affected version data listed by Google as "Android kernel." The supplied material does not enumerate specific Pixel models or build numbers; consult the vendor bulletin for that detail.
Patch Status
Google addressed the issue in the Pixel Update Bulletin dated 2026-09-01. CISA's required action is to apply vendor mitigations in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; where mitigations are unavailable, discontinue use of the product. The KEV entry flags forensic triage as required. The remediation due date was 2026-09-19: a three-day window from the KEV add date.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704
- Google Pixel Update Bulletin (September 2026), https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
- NVD, CVE-2026-58704, https://nvd.nist.gov/vuln/detail/CVE-2026-58704
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements), https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk