CTIPilot

Google Pixel cellular-modem zero-click privilege escalation, exploited in limited targeted attacks, CISA KEV 2026-09-16

cve · CVE-2026-58704

Coverage timeline
1
first 2026-09-17 → last 2026-09-17
Peak priority
high
1 high
Sources cited
5
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-17/cve-2026-58704-google-pixel-modem-zero-click-eop · ATT&CK page ↗

Story timeline

  1. 2026-09-17CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks
    trending-vulnerabilitiesGoogle patches a Pixel modem zero-day it says was already exploited in targeted attacks

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cisa.gov2 (40%)
  • cveawg.mitre.org1 (20%)
  • source.android.com1 (20%)
  • techcrunch.com1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Google Pixel cellular-modem zero-click privilege escalation, exploited in limited targeted attacks, CISA KEV 2026-09-16 (1)

2026-09-17 · view entry permalink →

HIGHCVE-2026-58704exploitedNATOA1

CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks

Google's September 2026 Pixel Update Bulletin fixes CVE-2026-58704 (bug A-484011314), a High-severity elevation-of-privilege flaw the bulletin classes as affecting the modem subcomponent (Google, 2026-09-15); the CVE's own MITRE record describes it as a possible permission bypass due to a logic error, reachable with no additional execution privileges and no user interaction needed for exploitation, a zero-click privilege escalation out of the modem's sandbox into the broader device (MITRE CVE record, 2026-09-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-16 (CISA, 2026-09-16), with a remediation due date of 2026-09-19, three days out (CISA KEV JSON feed, 2026-09-16). TechCrunch reports Google confirmed the bug "was exploited in limited and targeted cyberattacks" and that it is a zero-click flaw needing no victim interaction (TechCrunch, 2026-09-16); Google has not named a responsible actor. All supported Pixel devices receive the fix at the 2026-09-05 security patch level.

Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks.

The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.

TechCrunch 2026-09-16
vulnerability17 Sep 04:34Zmulti-sourceOpen finding ↗