logo

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability

ID: 9e8c0a7d-13ac-54a6-921d-5f13b19c31f9

STIX ID: report--9e8c0a7d-13ac-54a6-921d-5f13b19c31f9

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-09-17

Date Updated: 2026-09-17

...
...

**CVE-2026-58704 (Pixel modem permission-bypass):** Google patched a zero-click improper-authorization logic flaw in Pixel cellular modem firmware that allows remote (proximal/adjacent) privilege escalation without user interaction; the issue has an 8.0 CVSS score, was observed in limited targeted exploitation and added to CISA's KEV, and should be mitigated by installing the September 5, 2026 Pixel security update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.