๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-58704: Google Pixel Improper Authorization Vulnerability
Summary
Google Pixel devices have a security flaw in their cellular modem (the hardware that handles phone signals) that allows attackers to bypass permission checks and gain unauthorized access to the system through a logic error (a mistake in the code's decision-making). This vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from Google, following CISA's BOD 26-04 guidance for patching. If mitigations are unavailable, discontinue use of the product. Check the Android security bulletin at https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 for specific patch details.
Vulnerability Details
EPSS: 0.1%
Yes
๐ฅ Actively Exploited
September 15, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58704
First tracked: September 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%