Vulnerability
Published 2026-09-15
Verified 2026-09-19

Google Pixel Cellular Modem EoP CVE-2026-58704 (CVSS 8.0); limited targeted exploitation

Google’s September 2026 Pixel update (patch level 2026-09-05) addresses CVE-2026-58704 in the Cellular Modem: improper authorization / logic error enabling remote (proximal/adjacent) privilege escalation with low privileges, no user interaction. NVD (published 15 September 2026; Google as source) scores CVSS 3.1 8.0 (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). BleepingComputer (16 September 2026) cites Google’s Pixel bulletin warning of indications the flaw “may be under limited, targeted exploitation.” Same bulletin set covers 110 Pixel issues including additional critical/high RCE and privilege-escalation fixes. Distinct from desk card android-september-2026-bulletin (AOSP OEM bulletin). Apply Pixel Security update to 2026-09-05+. Primary: NVD CVE-2026-58704; wire: BleepingComputer; vendor bulletin URL (may require Google developer sign-in).

Product
Google Pixel (Cellular Modem / Android kernel per NVD affected data)
Versions
Affected Pixel builds before security patch level 2026-09-05; all supported Google Pixel devices receive the update per vendor/wire
CVSS
(CVSS 3.1, NVD secondary)
Exploited in Australia?
unknown
Patch to
Install Pixel Security update to patch level 2026-09-05 or newer (Settings > Security & privacy > System & updates > Security update)

Primary: NVD — CVE-2026-58704 (published 15 Sep 2026) · Vendor: Google Pixel security bulletin (Sep 2026 / 2026-09-05 patch level) · CVE: CVE-2026-58704 · BleepingComputer — Pixel zero-day CVE-2026-58704 (16 Sep 2026)

vulnerabilities network