Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-58704

Android

Google / Android · Android kernel

Severity
CVSS 8.8 · High
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
0.1%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-58704 is an unauthenticated vulnerability affecting Google Android. In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent)...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Google / Android android kernel.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed.

User interaction is not needed for exploitation.

Google Affected
Android
Android kernel
Published
15 Sep 2026
Exploitation Reported
16 Sep 2026
Attack vector
Adjacent
Complexity
Low
Privileges
None
User interaction
None

Tags

android cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Android

Recorded 16 Sep 2026

A trusted third party reported exploitation.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Android First 2026-09-16 08:15 UTC
CyberInsider 2026-09-16 09:29 UTC
CISA 2026-09-16 14:20 UTC
CVE 2026-09-16 14:50 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

8.8 High
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.1%

Recent mention · TheRegister

Google Pixel phones pwned in zero-click attacks

CISA gives federal agencies just 3 days to patch

Read full advisory

All Mentions

Recent mention · TheRegister

Google Pixel phones pwned in zero-click attacks

TheRegister · 16 Sep 2026

CISA gives federal agencies just 3 days to patch

Recent mention · TheHackerNews

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

TheHackerNews · 16 Sep 2026

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

Recent mention · CyberInsider

Google patches Pixel modem zero-day exploited in targeted attacks

CyberInsider · 16 Sep 2026

Google has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings supported devices to the 2026-09-05 security patch level. Google disclosed the vulnerability in its September 15 Pixel Update Bulletin, … The post Google patches Pixel modem zero-day exploited in targeted attacks appeared first on CyberInsider.

Timeline

From disclosure to observed exploitation

  1. 14:50 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  2. 14:20 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  3. 09:29 UTC

    KEV confirmed by CyberInsider

    Exploitation attested by an external source

  4. 08:15 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  5. 18:34 UTC

    CVE published

    Vulnerability disclosed publicly

  6. 05:38 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-58704

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-58704",
  "confidence": "Confirmed",
  "cvss_score": 8.8,
  "cvss_estimated": false,
  "epss_score": 0.00112,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}