Vulnerability record · CVE-2026-58704 · published 15 September 2026
CVE-2026-58704: Android Cellular Modem improper authorization allows adjacent privilege escalation
Google · Android
Android's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escalate privileges. The flaw requires no user interaction and no prior privileges, and the vendor advisory plus CISA KEV listing indicate it is serious enough to warrant urgent patching.
Description
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no privileges or user interaction required and CISA KEV listing with a three-day due date outweigh the low EPSS score.
What it is
Android's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escalate privileges. The flaw requires no user interaction and no prior privileges, and the vendor advisory plus CISA KEV listing indicate it is serious enough to warrant urgent patching.
Impact
An attacker in adjacent proximity gains high confidentiality, integrity and availability impact, effectively taking control of modem-level functionality on the affected device.
Attack surface
Reachable over an adjacent network (AV:A) via the cellular modem interface; no authentication (PR:N) and no user interaction (UI:N) are required.
Exploitation
CVE-2026-58704 was added to CISA KEV on 2026-09-16 with a three-day remediation due date, indicating known exploitation, though EPSS is low (0.00112, 1.5th percentile) and no ransomware use is documented.
What to do
- Apply the Google Pixel security bulletin update for 2026-09-01 as soon as possible.
- Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage requirements.
- If patching is not immediately possible, restrict or disable cellular modem connectivity where operationally feasible.
- Track affected Pixel devices in asset inventory and verify update compliance.
- Monitor vendor channels for any revised advisory or additional affected models.
Detection
- Review device logs for unexpected modem privilege or permission-check anomalies around the cellular interface.
- Hunt for abnormal modem-originated process activity or privilege transitions on managed Android devices.
- Correlate CISA KEV remediation status against endpoint management patch reports for Pixel devices.
- Monitor for anomalous adjacent-network radio activity targeting cellular modem stacks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities catalog on 16 September 2026 as "Google Pixel Improper Authorization Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704 | US Government Resource |
Track CVE-2026-58704 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-58704), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.