peter bassill · operator
$ cve CVE-2026-58704 JSON

CVE-2026-58704 KEV

8.8
HIGH · CVSS 3.1 · EPSS 0.6% (pctl 46)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-19.

Description

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.59% — more likely to be exploited than 46% of all CVEs
WeaknessCWE-285
On CISA KEVyes — remediate by 2026-09-19
Public exploitnone known
Published2026-09-15
Last modified2026-09-17

CISA KEV

NameGoogle Pixel Improper Authorization Vulnerability
Added2026-09-16
Due2026-09-19
Vendor / productGoogle / Pixel
Ransomware usenone reported

Affected (1)

VendorProduct
googleandroid

References

→ the Explorer  ·  watch your stack  ·  NVD