Google Pixel Cellular Modem Improper Authorization Vulnerability

Release Date: 21st September 2026 (Added 21 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and individuals that use Google Pixel devices. This alert is intended to be understood by both technical and general users.

What is it?

CVE-2026-58704 is a high-severity improper authorization vulnerability in the cellular modem component of Google Pixel devices. A logic error in the modem code allows a permission check to be bypassed, letting an attacker with adjacent or proximal network access (such as over the cellular network) escalate privileges and break out of the modem's isolated sandbox into the broader device.

No user interaction is required to exploit this flaw - it can be triggered as a zero-click attack, without the device owner tapping a link, opening a file, or taking any action. Google has confirmed indications that this vulnerability may be under limited, targeted exploitation; the zero-click, modem-level nature of the flaw is consistent with patterns historically associated with commercial spyware or state-aligned surveillance tools. CVSS v3.1 score: 8.0 (High).

Reference

  1. https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-58704