Google patches high-severity Pixel modem flaw CISA lists as exploited

Forkast News

Google patched high-severity Pixel modem flaw CVE-2026-58704, which lets attackers bypass permissions and escalate privileges without user interaction. It requires proximity to a device; Google says there are indications it may be exploited in limited, targeted attacks.

The September 2026 Pixel update, available since September 15, fixed 110 vulnerabilities. Four other modem flaws were included: two critical bugs—one remote-code-execution and one denial-of-service—and two high-severity bugs with the same respective impact types.

CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog on September 16. Federal civilian agencies had until September 19 to remediate under BOD 26-04. Google has not named an actor or disclosed a delivery method or target profile; the bug-tracker entry is private, and no proof of concept or indicators of compromise have been published.

#Google-Pixel-modem-flaw #CVE-2026-58704-exploitation
Share