---
schema: 1
kind: vulnerability
title: "CVE-2026-58704 — Google Pixel: zero-click privilege escalation out of the cellular modem sandbox, exploited in limited, targeted attacks"
headline: "Google patches a Pixel modem zero-day it says was already exploited in targeted attacks"
summary: >
  Google's September 2026 Pixel Update Bulletin (patch level 2026-09-05) fixes
  CVE-2026-58704, a logic error in the cellular modem that lets an attacker bypass permission
  checks and escalate out of the modem sandbox into the wider device with no user interaction.
  CISA added it to its Known Exploited Vulnerabilities catalog on 2026-09-16, and Google told
  TechCrunch the bug was exploited in limited, targeted attacks. Any Pixel device issued to
  staff who could plausibly be individually targeted needs the update now.
discovered_at: "2026-09-17T04:34:00Z"
updated_at: null
event_date: "2026-09-15"
run_id: 2026-09-17T0409Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, priv-esc, zero-click, actively-exploited, cisa-kev, mobile]
regions: [global]
sectors: [public-sector]
entities: []
techniques: [T1068]
affected_products: ["Google Pixel"]
cves:
  - id: CVE-2026-58704
    cvss: null
    epss: null
    type: priv-esc
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "Pixel devices at security patch levels before 2026-09-05"
    fixed: "2026-09-05 security patch level"
sources:
  - url: "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
    publisher: "Google (Pixel Update Bulletin)"
    date: "2026-09-15"
    role: primary
  - url: "https://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/"
    publisher: "TechCrunch"
    date: "2026-09-16"
    role: corroborating
  - url: "https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: "CISA (KEV addition alert)"
    date: "2026-09-16"
    role: corroborating
  - url: "https://cveawg.mitre.org/api/cve/CVE-2026-58704"
    publisher: "MITRE CVE record"
    date: "2026-09-16"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities catalog (JSON feed)"
    date: "2026-09-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks."
    publisher: "TechCrunch"
  - quote: "The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file."
    publisher: "TechCrunch"
verification: multi-source
sourcing_note: "CVSS not published by Google, the CNA, or NVD as of 2026-09-17; only the CISA-ADP Vulnrichment metrics block inside the MITRE CVE record carries a derived score (8.8, AV:A) without stating its own scoring rationale, so cvss is left null here rather than transcribed from that non-primary re-scoring."
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Push the 2026-09-05 Pixel security patch level to every managed Pixel device today, prioritising devices issued to personnel who could plausibly be individually targeted by surveillance-grade exploitation (police, government officials, diplomatic staff)."
updates: []
migrated_from: null
---

Google's September 2026 Pixel Update Bulletin fixes CVE-2026-58704 (bug A-484011314), a High-severity elevation-of-privilege flaw the bulletin classes as affecting the modem subcomponent ([Google, 2026-09-15](https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01)); the CVE's own MITRE record describes it as a possible permission bypass due to a logic error, reachable with no additional execution privileges and no user interaction needed for exploitation — a zero-click privilege escalation out of the modem's sandbox into the broader device ([MITRE CVE record, 2026-09-16](https://cveawg.mitre.org/api/cve/CVE-2026-58704)). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-16 ([CISA, 2026-09-16](https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-one-known-exploited-vulnerability-catalog)), with a remediation due date of 2026-09-19 — three days out ([CISA KEV JSON feed, 2026-09-16](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)). TechCrunch reports Google confirmed the bug "was exploited in limited and targeted cyberattacks" and that it is a zero-click flaw needing no victim interaction ([TechCrunch, 2026-09-16](https://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/)); Google has not named a responsible actor. All supported Pixel devices receive the fix at the 2026-09-05 security patch level.

**Defender takeaway:** confirm every managed Pixel device is at or past the 2026-09-05 patch level. Google has not attributed the exploitation to a named actor, and TechCrunch notes this class of modem bug is not uncommonly abused by commercial surveillance vendors selling access to governments and law-enforcement agencies — a pattern worth weighing for any Pixel fleet issued to staff whose role makes them a plausible individual surveillance target (police, government, diplomatic personnel), even though no such attribution has been confirmed here.
