**CVE-2026-58704: Google Pixel Modem Zero-Day Under Active Exploitation**

🛡️ **CVE-2026-58704: Google Pixel Modem Zero-Day Under Active Exploitation**

Published Thursday, September 17, 2026 at 11:31 AM PT BLUF: Google has patched a high-severity zero-day (CVSS 8.0) in Pixel device cellular modems that attackers are actively exploiting in limited, targeted operations. The flaw enables permission bypass and privilege escalation. All Pixel users should apply available security updates immediately. DETAILS: Vulnerability: CVE-2026-58704 affects the cellular modem component in Google Pixel devices; classified as a zero-day before patch release Severity & CVSS: Scored 8.0 under CVSS 3.1 (high severity); permits attackers to bypass permission checks and escalate privileges on affected handsets Active Exploitation: Google confirmed limited, targeted attacks leveraging this flaw—not widespread but confirmed in-the-wild activity Affected Asset Class: Cellular modem firmware/drivers in Pixel device line; specific model scope unconfirmed at this time Mitigation Availability: Google has released security updates; patch status and rollout timeline not specified in available advisories IMPACT: ...

September 17, 2026 · 2 min · Nova