Knox CVE Database
/
CVE-2026-58704
High
8.8

CVE-2026-58704: Google Pixel Improper Authorization Vulnerability

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Added to the CISA KEV catalog:
September 16, 2026

Overview

Google Pixel devices contain an improper authorization flaw in the cellular modem firmware. A logic error in the modem's permission-checking code allows an adjacent attacker to bypass authorization entirely and escalate privileges on the device without any user interaction or prior access. All Android kernel versions running on supported Pixel hardware are affected until the September 2026 security patch level is applied.

Vulnerability details

Affected vendor
Google
Affected product
Pixel
Weakness type (CWE)
CWE-693, CWE-285

The cellular modem on Pixel devices performs its own authorization checks to gate privileged modem operations. A logic error in that authorization path causes the checks to be bypassed rather than enforced, a failure that falls under both improper authorization (CWE-285) and protection mechanism failure (CWE-693). Because the modem processes inbound radio-layer traffic before the Android OS has any opportunity to inspect or filter it, the flaw sits at a trust boundary that is largely invisible to host-side security controls.


An attacker positioned in radio proximity to the target device, for example operating a rogue base station or otherwise able to inject cellular-layer traffic, sends crafted modem messages that trigger the logic error. The modem grants elevated privileges in response without verifying entitlement. No credentials, no user interaction, and no foothold on the device are required beforehand. The resulting privilege escalation carries high confidentiality, integrity, and availability impact, consistent with effective full-device compromise reachable purely from the cellular radio interface.

Severity and impact

8.8
High
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Adjacent
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Check the Android security patch level on all managed Pixel devices. Any device reporting a patch level earlier than 2026-09-05 remains vulnerable and should be treated as unpatched regardless of other controls.
  • Review MDM enrollment records for Pixel devices that have not received the September 2026 update within your expected patch window, as delayed or failed OTA updates leave the modem attack surface open with no compensating host-side control available.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 19, 2026

Additional hardening

  • Update all supported Pixel devices to the 2026-09-05 security patch level or later, which is the first patch level that addresses this modem authorization flaw per the September 2026 Pixel Update Bulletin.
  • Restrict or disable cellular connectivity on high-value Pixel devices in sensitive environments where a rogue base station attack is a credible threat; Wi-Fi-only operation removes the radio-layer attack surface entirely.
  • Where MDM is deployed, enforce a compliance policy that flags or quarantines Pixel devices below the required patch level, preventing them from accessing corporate resources until updated.
  • Treat unpatched Pixel devices as untrusted endpoints: segment them from internal networks and limit their access to sensitive data or systems until the patch is confirmed applied.

Key dates

Published (NVD)
September 15, 2026
Added to CISA KEV
September 16, 2026
Remediation deadline
September 19, 2026
Last updated
September 17, 2026

References

Frequently asked questions

Does CVE-2026-58704 affect my FedRAMP authorization?

If Google Pixel operates inside your authorization boundary, CVE-2026-58704 affects your Federal Risk and Authorization Management Program (FedRAMP) authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 19, 2026 that has already passed. An unpatched KEV inside your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Your options now are remediation or formal documentation of the mitigation and the delay.

How does Knox help me handle CVE-2026-58704?

Knox does not patch your software. Remediating CVE-2026-58704 in Google Pixel is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours. Managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-58704. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you a materially shorter window between disclosure and visibility.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-58704's remediation deadline of September 19, 2026 has passed. What happens now?

An unremediated CVE-2026-58704 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out now and documenting why the September 19, 2026 deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.