CVE Details
CVE-2026-58704
Google Pixel Improper Authorization Vulnerability
Published: 2026-09-16
CVSS: 8 HIGH
Product: Google Pixel
Due Date: 2026-09-19
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
GitHub PoC
Warning: GitHub PoC repositories are unverified. Some may be fake
or contain malware. Use caution and review code before running anything.
No GitHub PoC data.
FIRST EPSS
EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.
No EPSS data.
Timeline
CVE Stalker
KEV
MITRE
GitHub
FIRST (EPSS)
MITRE
CVSS
SSVC
References
Show Raw Data
| Key | Remaining Key | Value |
|---|---|---|
| dataType | CVE_RECORD | |
| dataVersion | 5.2 | |
| cveMetadata > | cveId | CVE-2026-58704 |
| cveMetadata > | assignerOrgId | 83238938-5644-45f0-9007-c0392bcf6222 |
| cveMetadata > | state | PUBLISHED |
| cveMetadata > | assignerShortName | Google_Devices |
| cveMetadata > | dateReserved | 2026-07-02T05:38:24.955Z |
| cveMetadata > | datePublished | 2026-09-15T18:34:37.966Z |
| cveMetadata > | dateUpdated | 2026-09-16T14:58:23.299Z |
| containers > | cna > providerMetadata > orgId | 83238938-5644-45f0-9007-c0392bcf6222 |
| containers > | cna > providerMetadata > shortName | Google_Devices |
| containers > | cna > providerMetadata > dateUpdated | 2026-09-15T18:34:37.966Z |
| containers > | cna > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | cna > problemTypes > 0 > descriptions > 0 > description | Elevation of privilege |
| containers > | cna > affected > 0 > vendor | |
| containers > | cna > affected > 0 > product | Android |
| containers > | cna > affected > 0 > versions > 0 > version | Android kernel |
| containers > | cna > affected > 0 > versions > 0 > status | affected |
| containers > | cna > affected > 0 > defaultStatus | unaffected |
| containers > | cna > descriptions > 0 > lang | en |
| containers > | cna > descriptions > 0 > value | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| containers > | cna > references > 0 > url | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 |
| containers > | cna > x_generator > engine | cvelib 1.7.1 |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > scope | UNCHANGED |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > version | 3.1 |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > baseScore | 8 |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > attackVector | ADJACENT_NETWORK |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity | HIGH |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > vectorString | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact | HIGH |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > userInteraction | NONE |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity | LOW |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact | HIGH |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired | LOW |
| containers > | adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact | HIGH |
| containers > | adp > 0 > metrics > 1 > other > type | ssvc |
| containers > | adp > 0 > metrics > 1 > other > content > id | CVE-2026-58704 |
| containers > | adp > 0 > metrics > 1 > other > content > role | CISA Coordinator |
| containers > | adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation | active |
| containers > | adp > 0 > metrics > 1 > other > content > options > 1 > Automatable | no |
| containers > | adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact | total |
| containers > | adp > 0 > metrics > 1 > other > content > version | 2.0.3 |
| containers > | adp > 0 > metrics > 1 > other > content > timestamp | 2026-09-16T14:40:04.611590Z |
| containers > | adp > 0 > metrics > 2 > other > type | kev |
| containers > | adp > 0 > metrics > 2 > other > content > dateAdded | 2026-09-16 |
| containers > | adp > 0 > metrics > 2 > other > content > reference | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704 |
| containers > | adp > 0 > references > 0 > url | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58704 |
| containers > | adp > 0 > references > 0 > tags > 0 | government-resource |
| containers > | adp > 0 > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | adp > 0 > problemTypes > 0 > descriptions > 0 > type | CWE |
| containers > | adp > 0 > problemTypes > 0 > descriptions > 0 > cweId | CWE-693 |
| containers > | adp > 0 > problemTypes > 0 > descriptions > 0 > description | CWE-693 Protection Mechanism Failure |
| containers > | adp > 0 > problemTypes > 1 > descriptions > 0 > lang | en |
| containers > | adp > 0 > problemTypes > 1 > descriptions > 0 > type | CWE |
| containers > | adp > 0 > problemTypes > 1 > descriptions > 0 > cweId | CWE-285 |
| containers > | adp > 0 > problemTypes > 1 > descriptions > 0 > description | CWE-285 Improper Authorization |
| containers > | adp > 0 > title | CISA ADP Vulnrichment |
| containers > | adp > 0 > providerMetadata > orgId | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| containers > | adp > 0 > providerMetadata > shortName | CISA-ADP |
| containers > | adp > 0 > providerMetadata > dateUpdated | 2026-09-16T14:58:23.299Z |
| containers > | adp > 0 > timeline > 0 > time | 2026-09-16T00:00:00.000Z |
| containers > | adp > 0 > timeline > 0 > lang | en |
| containers > | adp > 0 > timeline > 0 > value | CVE-2026-58704 added to CISA KEV |