ZeroHour
Story · 7 sources · 7 articlesfirst updated ()

Google patches actively exploited Pixel modem zero-day CVE-2026-58704 in September 2026 update

What's new: Two new reports arrived after the previous summary (written 2026-09-16T13:29:42Z): TechCrunch (14:47 UTC) adds that Google says some Pixel phone owners were hacked, that exploitation could allow escaping the modem sandbox to access broader phone data, and that surveillance-vendor abuse is considered likely though unattributed. Security Affairs (13:43 UTC) confirms the CVSS 8.0 score, adds…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Google's September 2026 Pixel Update Bulletin fixes 110 vulnerabilities, including CVE-2026-58704 (CVSS 8.0), a zero-click cellular modem privilege-escalation zero-day under limited, targeted exploitation; patch level 2026-09-05 or later fully remediates.

Google's September 2026 Pixel Update Bulletin fixes 110 vulnerabilities, including CVE-2026-58704, a high-severity privilege-escalation flaw in the Cellular Modem subcomponent of Pixel devices, scored CVSS 8.0 per The Hacker News and Security Affairs. Google acknowledges indications the flaw may be under limited, targeted exploitation but has not identified the threat actor, target count, or attack objectives; TechCrunch reports Google disclosed that some Pixel phone owners were hacked, while SecurityWeek speculates the zero-click modem nature suggests commercial spyware or state-sponsored actors, though this is unattributed. TechCrunch adds that exploitation could allow an attacker to escape the modem sandbox and escalate privileges to access broader phone data. Sources describe the root cause differently: BleepingComputer calls it an improper-authorization flaw, while Malwarebytes, The Hacker News, SecurityWeek, and Security Affairs describe it as a logic-error permission bypass. The bug has low attack complexity, requires adjacent/proximal network access, and needs no user interaction; sources phrase privilege prerequisites differently — BleepingComputer says basic privileges are required, Cyber Security News says no additional execution privileges are needed, and Malwarebytes says an existing foothold on the device is required, which the bulletin does not explain how to obtain. Malwarebytes notes the bug is useful in exploit chains combined with malicious apps, stolen credentials, or physical access, and Security Affairs notes the modem operates below much of the Android application security model. All 110 flaws are fixed at patch level 2026-09-05 or later, which appears only in the Pixel-specific bulletin, so other Android vendors do not receive this specific fix. Sources break down the bulletin's severity differently: BleepingComputer counts 12 remote code execution and 89 privilege-escalation flaws rated critical or high, Cyber Security News cites 12 critical RCEs, The Hacker News reports 46 critical-severity issues in components such as BigOcean, Bootloader, IMS, and the Trusted Execution Environment plus two high-severity kernel privilege-escalation bugs (CVE-2026-56914, CVE-2026-58773), and SecurityWeek says nearly 50 of the more than 100 other Pixel-specific flaws are critical, enabling RCE or privilege escalation. Security Affairs adds critical RCE flaws in IMS, libpixelimsmedia, VPU, modem, telephone, and BigOcean components. SecurityWeek…

  • CVE-2026-58704 is a high-severity (CVSS 8.0) privilege-escalation zero-day in the Pixel Cellular Modem; root cause is described as improper authorization (BleepingComputer) or a logic-error permission bypass (Malwarebytes, The Hacker News,…
  • Google acknowledges limited, targeted exploitation but provides no attribution, target count, or attack objectives; TechCrunch reports Google disclosed some Pixel phone owners were hacked.
  • Exploitation is zero-click (no user interaction), low complexity, and requires adjacent/proximal network access.
  • Privilege prerequisites are described differently: basic privileges (BleepingComputer), no additional execution privileges (Cyber Security News), or an existing foothold the bulletin does not explain how to obtain (Malwarebytes).
  • TechCrunch reports exploitation could enable modem sandbox escape and access to broader phone data; TechCrunch and SecurityWeek consider surveillance-vendor abuse likely but this is unattributed.
  • The September 2026 Pixel Update Bulletin fixes 110 vulnerabilities in total; patch level 2026-09-05 or later fully remediates all identified flaws.
  • Severity breakdowns conflict: 12 RCE and 89 privilege-escalation flaws rated critical/high (BleepingComputer); 12 critical RCEs (Cyber Security News); 46 critical issues plus two high-severity kernel EoP bugs CVE-2026-56914 and…
  • Components cited across reports include BigOcean, Bootloader, IMS, libpixelimsmedia, VPU, modem, telephone, and the Trusted Execution Environment.
VendorsGoogle
ProductsPixelAndroid
CountriesUnited States

Coverage timeline

  1. · 9h ago
    BleepingComputer· 78
    Google fixes actively exploited Android zero-day on Pixel devices

    Google patched 110 Pixel flaws including CVE-2026-58704, a modem privilege-escalation zero-day under limited targeted exploitation.

  2. · 6h ago
    Cyber Security News· 82
    Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

    Google patched CVE-2026-58704, an actively exploited Android zero-day allowing proximal privilege escalation via the Pixel cellular modem, urging the 2026-09-05 patch.

  3. · 5h ago
    Malwarebytes Labs· 68
    Google Pixel owners urged to patch actively exploited modem flaw

    Google's September 2026 Pixel bulletin fixes 110 vulnerabilities, including CVE-2026-58704, a modem permission bypass under limited targeted exploitation enabling remote privilege escalation.

  4. · 5h ago
    The Hacker News· 74
    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google's September Pixel update patches CVE-2026-58704, a high-severity cellular modem privilege escalation flaw showing signs of limited targeted exploitation.

  5. · 3h ago
    SecurityWeek· 74
    Pixel Modem Zero-Day Exploited in Targeted Attacks

    Google patched Pixel modem zero-day CVE-2026-58704, a zero-click permission bypass enabling remote privilege escalation, exploited in targeted attacks.

  6. · 2h ago
    Security Affairs· 74
    Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

    Google patched Pixel modem zero-day CVE-2026-58704 (CVSS 8.0), exploited in limited targeted attacks, enabling adjacent privilege escalation without user interaction.

  7. · 1h ago
    TechCrunch · Security· 78
    Google says some Pixel phone owners were hacked in zero-day attacks

    Google patched CVE-2026-58704, a zero-click Pixel modem privilege-escalation zero-day exploited in limited, targeted attacks.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48595
Integer Overflow Local Privilege Escalation in Android Framework

CVE-2025-48595 is an integer overflow (CWE-190) in the Android Framework, present in multiple locations, that can be triggered by code already running locally on the device with no additional execution privileges and no user interaction required. A local attacker, such as a malicious or compromised app, who triggers the overflow can achieve code execution with elevated privileges, yielding a local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.4, local attack vector). The flaw affects the Android Framework component of Google's Android operating system, so it applies broadly across the Android device ecosystem; specific affected version ranges were not published in the available data. Google fixed the flaw in its June 2026 Android security update, which patched 124 flaws overall, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-02, with news coverage confirming it is being actively exploited in the wild. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply Google's June 2026 Android security update (or later) to all Android devices as soon as the OEM build is available, and verify the device's 'Android security patch level' reads June 2026 or later before treating it as remediated. US federal agencies must remediate within the BOD 22-01 timelines per the KEV listing. Because exploitation requires local code execution, prioritize devices on which users can install or run untrusted apps, and use MDM tooling to track patch compliance across managed fleets.

8.42% KEV
  • Google Android
masshundreds of millions of Android devices potentially exposed (news coverage reports millions of affected devices)
CVE-2026-28662
Heap Buffer Overflow in Android Wi-Fi Direct (P2P) Provisioning Discovery Enables Nearby RCE

CVE-2026-28662 is a heap buffer overflow causing an out-of-bounds write in p2p_process_prov_disc_bootstrap_req in p2p_pd.c, the code that handles Wi-Fi P2P (Wi-Fi Direct) provisioning discovery bootstrap requests in Android's Wi-Fi stack. It is triggered when a nearby attacker sends a crafted bootstrap request over the air while the device's Wi-Fi is enabled; no user interaction or privileges are required. Successful exploitation yields remote (proximal/adjacent) code execution, meaning anyone within Wi-Fi radio range could run code on the device. Android devices running software prior to the September 2026 Android Security Update are affected. Exploitation is not currently observed: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.1%.

Do: Install the September 2026 Android Security Update (or your device vendor's equivalent build) as soon as it is available and verify the patch level in Settings > About phone. Until patched, consider disabling Wi-Fi Direct/peer-to-peer sharing and Wi-Fi when not needed, since exploitation requires proximity. The patch is part of the September 2026 release that fixes 180 vulnerabilities in total.

8.0<1%
  • Google / Android (CNA: [email protected]) Android OS Wi-Fi P2P (Wi-Fi Direct) stack, p2p_process_prov_disc_bootstrap_req in p2p_pd.c
massorder of billions of Android devices worldwide carry the affected Wi-Fi Direct code, though exploitation requires an attacker within radio range
CVE-2026-56914
Use-After-Free in Google Pixel Modem Enables Local Privilege Escalation

CVE-2026-56914 is a use-after-free condition caused by improper locking in multiple code locations in the modem component of Google Pixel smartphones, per Google's security bulletin coverage. An attacker can trigger the freed-memory race condition without needing any user interaction and without holding additional execution privileges. Successful exploitation yields local escalation of privilege on the affected device. All Pixel devices running firmware that predates Google's fix are potentially affected, with the specific impacted models and build numbers not enumerated in the available data. There is no public proof-of-concept and the flaw is not in CISA's KEV catalog, but Google's patch release is accompanied by reports of signs of limited, targeted exploitation.

Do: Install the latest Pixel/Android security bulletin update (Settings > System > System update) on all Pixel devices, prioritizing high-risk users such as journalists, executives, and government personnel given reports of targeted exploitation, and verify the security patch level after updating. No reliable mitigation is available beyond patching, since the flaw requires no user interaction or special privileges. Track Google's Pixel security bulletin for the definitive list of affected models and builds.

7.8
  • Google Pixel smartphones (modem component)
masstens of millions of Pixel devices in active use (order-of-magnitude estimate)
CVE-2026-58704
Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation

A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments.

Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios.

8.0 KEV
  • Google Cellular Modem (modem firmware on Google Pixel-class devices, per assigning CNA)
masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide)
CVE-2026-58773
Out-of-Bounds Write in Google Pixel Modem Link Driver Enables Local Privilege Escalation

CVE-2026-58773 is an out-of-bounds write (CWE-787) in link_load_gnss_image of link_device.c, the modem link device driver in the Android kernel used on Google Pixel phones, where a missing bounds check allows memory corruption when a GNSS image is loaded. To trigger it, an attacker must already have System-level code execution on the device; no user interaction is required. Successful exploitation corrupts memory outside the intended bounds and can yield local escalation of privilege, effectively moving an attacker from System context to higher (kernel-level) privileges. The flaw affects Google Pixel devices running the affected modem link driver, so exposure is limited to attackers who have already compromised a device or an app with System privileges. No public proof-of-concept exists and the bug is not in CISA KEV, but reporting indicates signs of limited, targeted exploitation, so it should be treated as exploited in the wild.

Do: Install the latest Google Pixel security update that addresses CVE-2026-58773 as soon as it is offered (Settings > System > System update), and verify the Android security patch level under Settings > About phone. Because exploitation requires System execution privileges and reporting suggests targeted misuse, prioritize high-risk users such as executives, journalists, and government personnel. There is no known remote mitigation; patching is the effective fix.

6.7
  • Google Pixel smartphones - Android kernel modem link device driver (link_device.c, link_load_gnss_image; Tensor/Exynos-modem Pi
masstens of millions of active Google Pixel handsets carrying the affected modem link driver