Severity: HighAction: PatchExploitation: ExploitedCISA KEV
Google Pixel Improper Authorization Vulnerability (CVE-2026-58704) is being actively exploited, CISA warns
CISA added CVE-2026-58704 (Google Pixel) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
Why it matters
CISA lists this as exploited in the wild. Unpatched Pixel systems are exposed to active attacks now.
Patch
Apply the vendor's security update for Pixel.
