Product

Pixel

Made by Google. 2 of its vulnerabilities are known to have been exploited.

Coverage

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Google Pixel Improper Authorization Vulnerability (CVE-2026-58704) is being actively exploited, CISA warns

CISA added CVE-2026-58704 (Google Pixel) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Why it matters

CISA lists this as exploited in the wild. Unpatched Pixel systems are exposed to active attacks now.

Patch

Apply the vendor's security update for Pixel.

Actively exploited

Google Pixel

Google Pixel Improper Authorization Vulnerability

Added Sep 16, 2026Fed. due Sep 19, 2026Coverage →

Google Pixel

Google Pixel Out-of-Bounds Write Vulnerability

Added Apr 11, 2022Fed. due May 2, 2022