Skip to content

Security1 publisher2 min readPublished

Google reports limited targeted exploitation of a Pixel cellular modem permission bypass

CVE-2026-58704 is a logic error in the cellular modem that lets an attacker within radio range, already holding basic privileges on the handset, escalate with no user interaction. It is one of 110 fixes in September's Pixel bulletin.

The Watch · Security desk

Photograph accompanying Google reports limited targeted exploitation of a Pixel cellular modem permission bypass
Photo: bleepingcomputer.com

What happened

  • Google shipped the September 2026 Pixel patches covering 110 vulnerabilities, one of them a zero-day the company says is under active exploitation in targeted attacks.
  • The other 109 issues in the bulletin include 12 remote code execution and 89 privilege escalation flaws rated critical or high severity.
  • The previous actively exploited case was in June, an Android Framework zero-day tracked as CVE-2025-48595 that hit devices running Android 14 or later.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The population at risk is narrow and specific: people whose handsets sit within radio range of an attacker who has already landed something with basic privileges on the device.
  • decision Exploitation is reported and the path needs no tap from the user, so handset patching now competes with server patching for the same maintenance window.
  • constraint Confirming Pixels at the 2026-09-05 level closes only part of a mixed Android fleet; every other vendor's devices have to be checked against their own bulletins on their own dates.

"Adjacent network" is the attack vector, and it fixes the preconditions an attacker has to meet. By Google's account the attacker has to be within radio range of the target and already hold basic privileges on the handset; from there the modem logic error yields escalation in a low-complexity attack with no user interaction [4]. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," the advisory said, and the result is "remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed" [5][6]. So this is a step in a chain. Something else has to get code onto the phone first.

Google's one sentence is the whole public record on the exploitation: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company said on Wednesday [2]. The advisory as reported does not name an actor or a victim, and it lists no indicators of compromise [14]. The same "targeted" language covered June's Android Framework zero-day, CVE-2025-48595, which Google patched after active exploitation against devices running Android 14 or later [11].

The rest of the bulletin is bulk maintenance. Of the 109 other issues, Google broke out 12 remote code execution and 89 privilege escalation flaws rated critical or high [7]. That accounts for 101, leaving 8 the summary does not categorise [13]. Privilege escalation is roughly four in five of the month's non-zero-day fixes [15].

The level to verify is 2026-09-05. "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices," Google said [8]. Installation sits with whoever holds the device: Settings, then Security and privacy, then System and updates, then Security update, then Install and a restart [10]. On a handset nobody manages, that sequence is the entire patch programme.

Pixel is on its own release train. Google ships Pixel fixes separately from the monthly patches it distributes to other Android OEMs, because it controls the hardware platform and the exclusive features that run on it [9]. A month before the June zero-day, the company also rebuilt its Android and Chrome reward programs, cutting payouts for flaws that are easier to find with AI while raising the top end to $1.5 million for some Android exploits [12].

What to watch

  • Whether Google's general Android bulletin lists the same modem CVE for non-Pixel devices, which would widen the affected population well beyond Pixel.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories