2026-09-17 · view entry permalink →
CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks
Google's September 2026 Pixel Update Bulletin fixes CVE-2026-58704 (bug A-484011314), a High-severity elevation-of-privilege flaw the bulletin classes as affecting the modem subcomponent (Google, 2026-09-15); the CVE's own MITRE record describes it as a possible permission bypass due to a logic error, reachable with no additional execution privileges and no user interaction needed for exploitation, a zero-click privilege escalation out of the modem's sandbox into the broader device (MITRE CVE record, 2026-09-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-16 (CISA, 2026-09-16), with a remediation due date of 2026-09-19, three days out (CISA KEV JSON feed, 2026-09-16). TechCrunch reports Google confirmed the bug "was exploited in limited and targeted cyberattacks" and that it is a zero-click flaw needing no victim interaction (TechCrunch, 2026-09-16); Google has not named a responsible actor. All supported Pixel devices receive the fix at the 2026-09-05 security patch level.
Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks.
The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.