Cybersecurity

Exploited Pixel Modem Flaw Rated 8.8; CISA Deadline Sept 19

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Exploited Pixel Modem Flaw Rated 8.8; CISA Deadline Sept 19
Photo: Google (official Pixel product image)
0 0
XWhatsAppTelegramLinkedIn

Google has patched a vulnerability in the Pixel cellular modem that its own engineers say may already have been used against real targets. The flaw, tracked as CVE-2026-58704, appears in the Pixel Update Bulletin published on 15 September 2026, where Google states there are “indications that CVE-2026-58704 may be under limited, targeted exploitation.” The bulletin classifies it as an elevation-of-privilege issue of High severity in the Modem component, and says a security patch level of 2026-09-05 or later resolves it.

The story moved beyond a routine bulletin note a day later. On 16 September the U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog under the name “Google Pixel Improper Authorization Vulnerability,” describing a logic error that “may allow an attacker to bypass permission checks and escalate privileges.” Federal civilian agencies were given until 19 September 2026 to remediate under Binding Operational Directive 26-04 — a three-day window. CISA’s entry also marks the vulnerability as subject to its forensic triage requirements, and lists known ransomware use as “Unknown.”

What makes the bug notable for ordinary Pixel owners is the interaction it requires: none. The National Vulnerability Database entry, published on 15 September, reads: “In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” The Hacker News, which first reported the KEV addition, described it as a zero-click attack, because the owner never has to tap a link or open a file. The CVSS 3.1 score recorded in the NVD entry, assigned by CISA, is 8.8 (High), with an attack vector of “adjacent network” — meaning an attacker needs radio or network proximity to the handset rather than a path from anywhere on the internet.

Several things remain unknown. Google did not name the attackers, say how many devices were hit, or describe the attack chain, and it has not published a list of affected Pixel models beyond noting that all supported Google devices will receive the 2026-09-05 patch level. The same bulletin closes 110 vulnerabilities in total, 46 of which Google rates Critical, including remote code execution flaws in components such as the IP Multimedia Subsystem and the bootloader. The practical step for users is unchanged: check the device security patch level and install the September update if it has not arrived yet.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.