Exploited Pixel Modem Flaw Rated 8.8; CISA Deadline Sept 19

Google has patched a vulnerability in the Pixel cellular modem that its own engineers say may already have been used against real targets. The flaw, tracked as CVE-2026-58704, appears in the Pixel Update Bulletin published on 15 September 2026, where Google states there are “indications that CVE-2026-58704 may be under limited, targeted exploitation.” The bulletin classifies it as an elevation-of-privilege issue of High severity in the Modem component, and says a security patch level of 2026-09-05 or later resolves it.
The story moved beyond a routine bulletin note a day later. On 16 September the U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog under the name “Google Pixel Improper Authorization Vulnerability,” describing a logic error that “may allow an attacker to bypass permission checks and escalate privileges.” Federal civilian agencies were given until 19 September 2026 to remediate under Binding Operational Directive 26-04 — a three-day window. CISA’s entry also marks the vulnerability as subject to its forensic triage requirements, and lists known ransomware use as “Unknown.”
What makes the bug notable for ordinary Pixel owners is the interaction it requires: none. The National Vulnerability Database entry, published on 15 September, reads: “In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” The Hacker News, which first reported the KEV addition, described it as a zero-click attack, because the owner never has to tap a link or open a file. The CVSS 3.1 score recorded in the NVD entry, assigned by CISA, is 8.8 (High), with an attack vector of “adjacent network” — meaning an attacker needs radio or network proximity to the handset rather than a path from anywhere on the internet.
Several things remain unknown. Google did not name the attackers, say how many devices were hit, or describe the attack chain, and it has not published a list of affected Pixel models beyond noting that all supported Google devices will receive the 2026-09-05 patch level. The same bulletin closes 110 vulnerabilities in total, 46 of which Google rates Critical, including remote code execution flaws in components such as the IP Multimedia Subsystem and the bootloader. The practical step for users is unchanged: check the device security patch level and install the September update if it has not arrived yet.
Sources
- Android Open Source Project — Pixel Update Bulletin, September 2026Primary source
- CISA — Adds One Known Exploited Vulnerability to CatalogPrimary source
- NIST National Vulnerability Database — CVE-2026-58704Primary source
- The Hacker NewsSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.