Home Β· Wiki Β· Vulnerabilities & CVEs
type: cve Β· created: 2026-09-17 Β· updated: 2026-09-17 Β· tags: [cve, exploited, privilege-escalation] Β· confidence: high Β· severity: high Β· affected_sectors: [global] Β· au_impact: false

A permission bypass in the cellular modem of Google Pixel devices, caused by a logic error in the code. NVD records it as analysed with a score of 8.8 (High, CVSS 3.1); Google says the flaw shows signs of limited, targeted exploitation, and CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September 2026.

Attribute Detail
CVE CVE-2026-58704
CVSS 8.8 (High, CVSS 3.1)
Vendor / product Google / Pixel β€” Cellular Modem component
Reported 2026-09-16

Exploitation leads to remote (proximal or adjacent) escalation of privilege with no additional execution privileges and no user interaction, meaning the attacker has to be within radio range of the device rather than reachable over the internet. That proximity requirement shapes the targeting profile: baseband flaws of this class are usually issued to high-value individuals rather than exploited opportunistically, which is why the KEV listing is a patching obligation for federal agencies rather than a mass-exploitation warning, and why Pixel owners in sensitive roles should treat the monthly platform update as a deadline rather than a convenience.