news.mlab.sh
Back to the feed
vulnerability

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

HighCVSS 8.4
Summary

Google has patched a critical vulnerability in its Pixel cellular modem, which was already being exploited in the wild. The flaw allows for privilege escalation without user interaction, and Google has released a security update to address it, alongside numerous other security fixes within the September 2026 Pixel updates.

Google has disclosed a high-severity security vulnerability in its Pixel Cellular Modem, tracked as CVE-2026-58704 (CVSS score: 8.0). The vulnerability is a privilege escalation flaw, meaning an attacker could gain elevated permissions on the device without requiring any user interaction. According to the NIST National Vulnerability Database, the issue stems from a logic error in the code, leading to a potential permission bypass. Google has confirmed that it has detected signs of limited, targeted exploitation of this vulnerability.

Beyond CVE-2026-58704, Google has released a comprehensive security update for Pixel devices, addressing 109 additional security flaws within the September 2026 updates. Of these, a significant portion – 88 – allow privilege escalation, 10 allow information disclosure, nine allow remote code execution, and two allow denial-of-service (DoS). Specifically, two high-severity privilege escalation vulnerabilities exist within Kernel components (CVE-2026-56914 and CVE-2026-58773), alongside 46 critical-severity vulnerabilities in components like BigOcean, Bootloader, IP Multimedia Subsystem, and Trusted Execution Environment.

To resolve these issues, users are advised to update their Pixel devices to security patch level 2026-09-05 or later. This can be done by navigating to Settings > Security & privacy. Notably, this vulnerability follows on from a similar issue addressed in June 2026, where Google patched a high-severity flaw in Android's Framework component (CVE-2025-48595, CVSS score: 8.4) that was also under active exploitation at the time.

Read the full article at The Hacker News