← Vulnerability feed

Vulnerability record · CVE-2026-58704 · published 15 September 2026

CVE-2026-58704: Android Cellular Modem improper authorization allows adjacent privilege escalation

Google · Android

Android's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escalate privileges. The flaw requires no user interaction and no prior privileges, and the vendor advisory plus CISA KEV listing indicate it is serious enough to warrant urgent patching.

8.8 CVSS 3.1 High CISA KEV since 16 Sep 2026 EPSS 0.59% · top 53.9% CWE-285 · Improper authorizationCWE-693 · CWE-693
8.8CVSS 3.1 base score
0.59%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Sep 2026Last modified by NVD

Description

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no privileges or user interaction required and CISA KEV listing with a three-day due date outweigh the low EPSS score.

What it is

Android's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escalate privileges. The flaw requires no user interaction and no prior privileges, and the vendor advisory plus CISA KEV listing indicate it is serious enough to warrant urgent patching.

Impact

An attacker in adjacent proximity gains high confidentiality, integrity and availability impact, effectively taking control of modem-level functionality on the affected device.

Attack surface

Reachable over an adjacent network (AV:A) via the cellular modem interface; no authentication (PR:N) and no user interaction (UI:N) are required.

Exploitation

CVE-2026-58704 was added to CISA KEV on 2026-09-16 with a three-day remediation due date, indicating known exploitation, though EPSS is low (0.00112, 1.5th percentile) and no ransomware use is documented.

What to do

  • Apply the Google Pixel security bulletin update for 2026-09-01 as soon as possible.
  • Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage requirements.
  • If patching is not immediately possible, restrict or disable cellular modem connectivity where operationally feasible.
  • Track affected Pixel devices in asset inventory and verify update compliance.
  • Monitor vendor channels for any revised advisory or additional affected models.

Detection

  • Review device logs for unexpected modem privilege or permission-check anomalies around the cellular interface.
  • Hunt for abnormal modem-originated process activity or privilege transitions on managed Android devices.
  • Correlate CISA KEV remediation status against endpoint management patch reports for Pixel devices.
  • Monitor for anomalous adjacent-network radio activity targeting cellular modem stacks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities catalog on 16 September 2026 as "Google Pixel Improper Authorization Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 19 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-58704 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed7.8CVE-2021-39793Android Mali GPU driver out-of-bounds write in kbase_jd_user_buf_pin_pagesThe Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write…KEVEPSS 0.69%analysed

Source: NIST National Vulnerability Database (record CVE-2026-58704), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.