In the Pixel Update Bulletin for September 2026, published on 15 September 2026, Google fixed CVE-2026-58704, a permission bypass in the cellular modem. The bulletin carries this note: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation."
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on 16 September 2026.
There is one thing to do: get your device to security patch level 2026-09-05 or later. Checking takes about a minute in Settings.
What to do right now
- ✓Check your security patch level. On a Pixel, open Settings → Security & privacy → System & updates → Security update. If it reads 2026-09-05 or later, the fix is installed.
- ✓If it is older, download the update and finish the restart. Downloading alone does not apply it. The vulnerable modem software keeps running until the device has rebooted.
- ✓If no update appears yet, check again later. Rollouts are staged, so two identical models can receive it days apart.
- ✓Pixel devices past their update window will not receive this fix. The bulletin covers supported Pixel (Google) devices. Check your model's update window on Google's support page.
- ✓If you manage devices for an organisation, inventory them by patch level. CISA set 19 September 2026 as the remediation deadline for US federal agencies.
Where that score comes from. The 8.8 above was assigned by CISA-ADP under CVSS v3.1, with vector `CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`.
Google (Google_Devices), the CNA for this record, published no CVSS metric at all, and NIST has not added one either. The only CVSS on this CVE is CISA-ADP's.
Google expresses its own assessment through the bulletin's own scheme rather than a CVSS number: severity High, type EoP (elevation of privilege), subcomponent Modem. The two do not conflict — both land on "High".
The urgency is not the score — it is that attackers already used it
A severity rating estimates how bad it would be if exploited. Whether it is being exploited right now is separate information.
This CVE falls into the second category. Google placed this note near the top of the bulletin:
Pixel Update Bulletin—September 2026 (published 15 September 2026)
Note: There are indications that CVE-2026-58704 may be
under limited, targeted exploitation.Google's wording is deliberately hedged — "there are indications" and "may be" — and it does not claim to describe the full picture. "Limited, targeted" characterises what Google observed; it is not a guarantee that no other exploitation exists.
Separately, CISA added this CVE to the KEV catalog on 16 September 2026 as a known exploited vulnerability. What is established is that it was used in real attacks; how far that activity extends is not something the public sources tell us. "I am not important enough to be targeted" is a poor trade against a task that takes a few minutes.
What the flaw actually is
The cellular modem, or baseband, is the dedicated part of a phone that handles the mobile network. It runs its own software, separate from your apps, and you never see it.
NVD describes the issue as a permission bypass caused by a logic error, leading to elevation of privilege with no additional execution privileges and no user interaction required. In other words, it does not depend on you tapping a bad link or installing an app. The usual assumption — that you are safe as long as you avoid risky actions — does not hold for this one.
There is a limit on where an attacker has to be, though. The CVSS vector starts with `AV:A` (Adjacent), and NVD describes the reach as "remote (proximal/adjacent)". This is not the kind of flaw that lets anyone on the internet reach every handset. It requires proximity — radio range or the same network segment.
That is not a reason to relax; it is consistent with the targeted-attack reporting. Treat it as a hole that closes when you update, and close it today.
Working out whether your device is affected
The bulletin covers supported Pixel (Google) devices. This article deliberately does not print a model list: reading the patch level on the device in your hand is more reliable than matching a model name.
- ▸Patch level 2026-09-05 or later — you have the fix, along with everything else in this bulletin and in the September 2026 Android Security Bulletin
- ▸2026-09-01, or anything earlier than 5 September — you do not have it yet; update
- ▸Stuck on August or earlier with no update offered — your device's update window may have ended. Check your model's support period on Google's page
- ▸Non-Pixel Android devices — this CVE was addressed in the Pixel bulletin. For other manufacturers, check their own update advisories. We will not guess at other vendors' status here
- Google: Pixel Update Bulletin—September 2026 (15 September 2026; exploitation note and patch level 2026-09-05)↗
- NVD: CVE-2026-58704 (CVSS v3.1 8.8 HIGH / CWE-285, CWE-693)↗
- CISA: Known Exploited Vulnerabilities Catalog (added 16 September 2026, due 19 September 2026)↗
- Google: Check and update your Android version and security patch level↗
- Google: Pixel update windows by model↗
