
(CVE-2026-58704)[484011314][Modem]Logic error->permission bypass->EoP(proximal/adjacent) in Cellular Modem, exploited ITW https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01#pixel
Signal is active with 11 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-19. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

(CVE-2026-58704)[484011314][Modem]Logic error->permission bypass->EoP(proximal/adjacent) in Cellular Modem, exploited ITW https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01#pixel

Google: actively exploited Pixel zero-day CVE-2026-58704 in September modem patches (110 flaws total). Limited targeted attacks. Adjacent priv-esc, no user click needed. Patch Pixel fleets to 2026-09-05 now. #CyberSecurity #Android #CVE Link: https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/

Android Pixel CVE-2026-58704: "In Cellular Modem, there is a possible permission bypass due to a logic error(.) This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation." https://t.co/hrRQu0nvYd

Pixel Sept patch: zero-day in the cellular modem. CVE-2026-58704 — logic bug = permission bypass. Adjacent network + light foothold, then escalate. No tap. Google: limited targeted. not drive-by-from-anywhere. Take patch level 2026-09-05.

Breaking: A dangerous zero-day (CVE-2026-58704) in Pixel modems is being weaponized in targeted attacks. No user interaction needed. The September 5, 2026 Pixel patch fixes it—install now to protect against privilege escalation, remote threat vectors, and risks to data integrity. #Pixel #ZeroDay #AndroidSecurity #ModemExploit #CVE2026-58704 #Cybersecurity https://thedailytechfeed.com/serious-modem-zero-day-in-pixel-phones-actively-exploited/

csirt_it: ‼️ #Exploited #Google: rilevato sfruttamento attivo in rete della CVE-2026-58704 per dispositivi #Pixels Rischio: 🔴 Tra le tipologie: 🔸 Remote Code Execution 🔸 Elevation of Privilege 🔗 https://www.acn.gov.it/portale/w/aggiornamenti-di-sicurezza-per-dispositivi-google-pixel-7 ⚠️ Importante mantenere agg… https://t.co/255YDwfLzL
Google Pixel Flaw CVE-2026-58704 Exploited in Targeted Attacks - https://securityonline.info/google-pixel-vulnerability-exploited/

THREATLOOM // SIGNAL Google confirms targeted exploitation of CVE-2026-58704 against Pixel devices. This one isn't WebView or Chrome. It's the cellular modem. modem logic error → permission bypass → remote/proximal privilege escalation → no user interaction Google is withholding the underlying bug details and says exploitation appears limited and targeted. Important patch detail: 2026-09-05, not merely 2026-09-01. For high-risk Pixel users, verify the actual security patch level rather than assuming an available September update means the device contains this fix. The exploitation chain is still undisclosed. Don't turn “modem” into “internet-remotely exploitable” until Google publishes more. https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/

Google Patches Actively Exploited Pixel Modem Zero-Day CVE-2026-58704 Google releases September 2026 security updates for Pixel devices, patching active zero-day CVE-2026-58704 alongside 109… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #google https://t.co/MSALjhwkpg

🚨 GOOGLE PIXEL ZERO-DAY: Actively exploited flaw patched Google has released its September 2026 Pixel security update, fixing 110 vulnerabilities — including a zero-day reportedly being exploited in limited, targeted attacks. ⚠️ CVE-2026-58704 • High severity • Affects the Cellular Modem • Allows a permission bypass • Could enable remote/adjacent privilege escalation • Requires no user interaction • Exploitation is described as low complexity 🔥 The update also addresses: 1. 12 remote code execution flaws 2. 89 privilege escalation vulnerabilities 📱 If you own a supported Pixel device, update now: Settings → Security & privacy → System & updates → Security update → Install #GooglePixel #Android #ZeroDay #CVE #MobileSecurity #Exploit #GoogleSecurity

📡 Pixel’s September patch fixes a high-severity modem flaw already showing signs of targeted exploitation. No app, no tap, just an adjacent network—patching suddenly sounds less optional. https://windowsforum.com/news/cve-2026-58704-pixel-modem-exploit-fixed-by-2026-09-05-patch.444613/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MobileSecurity #PixelSecurity #AndroidUpdates #Cve202658704 https://t.co/q6CJkBBHBe

GoogleがPixel向け9月セキュリティ更新を公開 — モデムの権限昇格CVE-2026-58704が「限定的な標的型攻撃」で悪用された可能性 https://cyber.nexsight.co/articles/2026/09/16/google-pixel-android-september-2026-bulletin-cve-2026-58704-2026-09-16/
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | android | - | - | - |