What it is
CVE-2026-58704 is an unauthenticated vulnerability affecting Google Android. In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent)...
Vulnerability report
Android
Google / Android · Android kernel
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-58704 is an unauthenticated vulnerability affecting Google Android. In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent)...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Google / Android android kernel.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed.
User interaction is not needed for exploitation.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Android
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Android First | 2026-09-16 08:15 UTC |
| CyberInsider | 2026-09-16 09:29 UTC |
| CISA | 2026-09-16 14:20 UTC |
| CVE | 2026-09-16 14:50 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.1%
Recent mention · TheRegister
CISA gives federal agencies just 3 days to patch
Read full advisoryRecent mention · TheRegister
Google Pixel phones pwned in zero-click attacksTheRegister · 16 Sep 2026
CISA gives federal agencies just 3 days to patch
Recent mention · TheHackerNews
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationTheHackerNews · 16 Sep 2026
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
Recent mention · CyberInsider
Google patches Pixel modem zero-day exploited in targeted attacksCyberInsider · 16 Sep 2026
Google has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings supported devices to the 2026-09-05 security patch level. Google disclosed the vulnerability in its September 15 Pixel Update Bulletin, … The post Google patches Pixel modem zero-day exploited in targeted attacks appeared first on CyberInsider.
Timeline
14:50 UTC
Exploitation attested by an external source
14:20 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
09:29 UTC
Exploitation attested by an external source
08:15 UTC
High-confidence, third-party attested exploitation
18:34 UTC
Vulnerability disclosed publicly
05:38 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-58704
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-58704",
"confidence": "Confirmed",
"cvss_score": 8.8,
"cvss_estimated": false,
"epss_score": 0.00112,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}