Status: KEV
| Advisory ID: CVE-2026-58704
Key Details
| CVE | CVE-2026-58704 |
| Vulnerability Name | Google Pixel Improper Authorization Vulnerability |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-09-18 |
| CVSS Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Google Pixel |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-16. |
| Exploitation prediction (EPSS) | 0.59% probability of exploitation in the next 30 days (46% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
What to Do
Monitor Google's web page for any future patch releases. See vendor advisory link below.
References
KEV Required Action