CVE-2026-58704, Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks
Google patches a Pixel modem zero-day it says was already exploited in targeted attacks
Defender actions
- Push the 2026-09-05 Pixel security patch level to every managed Pixel device today, prioritising devices issued to personnel who could plausibly be individually targeted by surveillance-grade exploitation (police, government officials, diplomatic staff).
Analysis
Google's September 2026 Pixel Update Bulletin fixes CVE-2026-58704 (bug A-484011314), a High-severity elevation-of-privilege flaw the bulletin classes as affecting the modem subcomponent (Google, 2026-09-15); the CVE's own MITRE record describes it as a possible permission bypass due to a logic error, reachable with no additional execution privileges and no user interaction needed for exploitation, a zero-click privilege escalation out of the modem's sandbox into the broader device (MITRE CVE record, 2026-09-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-16 (CISA, 2026-09-16), with a remediation due date of 2026-09-19, three days out (CISA KEV JSON feed, 2026-09-16). TechCrunch reports Google confirmed the bug "was exploited in limited and targeted cyberattacks" and that it is a zero-click flaw needing no victim interaction (TechCrunch, 2026-09-16); Google has not named a responsible actor. All supported Pixel devices receive the fix at the 2026-09-05 security patch level.
Cited evidence
Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks.
The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.
Sources5
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.