Updated
Updated · The Hacker News · Sep 16
CISA Flags Pixel Modem Flaw CVE-2026-58704, Orders Federal Patches by Sept. 19
Updated
Updated · The Hacker News · Sep 16

CISA Flags Pixel Modem Flaw CVE-2026-58704, Orders Federal Patches by Sept. 19

2 articles · Updated · The Hacker News · Sep 16

Summary

  • Sept. 16, CISA added Google Pixel modem bug CVE-2026-58704 to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until Sept. 19 to apply fixes.
  • Google said the flaw—rated 8.0—has seen limited, targeted exploitation in the wild; the logic error lets attackers bypass permission checks and escalate privileges without user interaction.
  • The bug can be used in zero-click attacks, allowing silent compromise of nearby Pixel devices through the cellular modem with no link click or file open required.
  • Google fixed CVE-2026-58704 in its September 2026 Pixel update, which also patched 109 other flaws; devices on security patch level 2026-09-05 or later are protected.

Insights

Why did CISA issue an urgent mandate to patch a hidden modem flaw that operates completely beneath standard Android security protections?
Who is deploying this silent, zero-click cellular exploit to hijack Pixel phones from nearby without any user interaction?