Skip to main content
QUIETLYTIC
Vulnerability

Google Pixel Privilege Escalation (CVE-2026-58704)

CVE-2026-58704 is a CVSS 8.8 permission bypass in the Pixel cellular modem, confirmed exploited per CISA and VulnCheck KEV.

CVE-2026-58704
Threat Level
HIGH
CVSS
8.8
Status
Active Exploitation
Confidence
High
Affected Products
Google Pixel, Android (Cellular Modem component)

CVE-2026-58704 carries a CVSS 3.1 base score of 8.8 against the cellular modem component of Google Pixel devices. NVD classifies it under both CWE-285 (Improper Authorization) and CWE-693 (Protection Mechanism Failure); CISA’s own KEV entry and VulnCheck’s KEV feed both classify it as CWE-693 alone. CISA added this CVE to its Known Exploited Vulnerabilities catalog on September 16, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD and CVE.org’s shared description states the flaw is a permission bypass in the cellular modem caused by a logic error in the code, leading to escalation of privilege. Both sources classify the attack vector as AV:A — adjacent network — meaning it requires an attacker to be proximally or logically adjacent to the target rather than reachable over the open internet, a meaningfully narrower exposure than a fully remote flaw. The vector otherwise requires no privileges and no user interaction (PR:N, UI:N).

Our source data does not carry the specific modem subsystem or code path beyond that description; Google’s own Android Security Bulletin for Pixel devices, linked from both NVD and CVE.org, is the authoritative technical source.

Evidence and confidence

  • High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated September 16, 2026.
  • High confidence — the affected product (Pixel devices, per CISA KEV and VulnCheck KEV) and the underlying Android platform attribution, per CVE.org.
  • Medium confidence — the CVSS 8.8 score and vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which trace to NVD alone in our current ingestion. The CWE classification carries a minor split: NVD lists both CWE-285 and CWE-693, while CISA KEV and VulnCheck KEV list CWE-693 only — not a conflict, but an incomplete overlap worth noting.
  • Low exploitation probability by EPSS — FIRST’s EPSS model scores this CVE at 0.00112, a 1.6th percentile score as of our ingestion, notably low for a confirmed CISA KEV entry and a reminder that EPSS and confirmed-exploitation status can diverge.

No field is in direct conflict between our sources.

Why this matters

The adjacent-network attack vector is the detail most likely to get lost in a quick read of this CVE: this is not a flaw exploitable from anywhere on the internet, but one requiring physical or logical proximity to the target device, consistent with a baseband/cellular-modem attack surface. That narrower exposure doesn’t reduce the severity of a confirmed, actively exploited privilege escalation — it changes the threat model to one involving proximate attackers (rogue cell infrastructure, physically nearby adversaries) rather than opportunistic mass scanning.

CISA’s confirmation of exploitation, corroborated independently by VulnCheck, places this in the same urgency tier as our other confirmed-KEV coverage this cycle, and BOD 26-04’s remediation clock is already running for in-scope federal agencies with affected Pixel devices in their fleets.

Frequently Asked Questions

What is CVE-2026-58704? A CVSS 8.8 permission bypass (CWE-285/CWE-693) in the cellular modem component of Google Pixel devices, allowing an adjacent-network attacker to escalate privileges with no user interaction and no privileges required.

Is CVE-2026-58704 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated September 16, 2026.

Does an attacker need to be on the internet to exploit this? No. The CVSS vector specifies an adjacent-network attack vector, meaning the attacker needs proximate access — such as nearby wireless/cellular positioning — rather than unrestricted internet reach.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which devices are affected? Google Pixel devices, per CISA KEV and VulnCheck KEV. Consult Google’s Android Security Bulletin for the specific patch level that resolves this issue.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-58704 and the CVE.org record. Exploitation status and the September 16, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Google’s own advisory: Android Security Bulletin — Pixel Update, September 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CVE.org
03 CISA Known Exploited Vulnerabilities (KEV) Catalog
04 VulnCheck KEV

Related intelligence


Analyst tools