Close Menu
NCIJ Network NCIJ Network
    What's Hot

    One dead after torrential rain and flash floods hit Barcelona region

    September 17, 2026

    Apple Watch Series 12 Review: Finally, a Readiness Score (2026)

    September 17, 2026

    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • One dead after torrential rain and flash floods hit Barcelona region
    • Apple Watch Series 12 Review: Finally, a Readiness Score (2026)
    • Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
    • SEC rolls out ‘innovation exemption’ for tokenized securities trading venues
    • NASA Astronaut Reid Wiseman to Join NFL Fans in Baltimore
    • World’s smallest crocodile in high demand for bushmeat trade in Nigeria
    • British people understand the climate crisis threat. Today I’m empowering them to tackle it | Andy Burnham
    • What’s the Asian Games accommodation crisis, and where will athletes stay? | Housing
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 17, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 16, 2026Vulnerability / Mobile Security

    Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild.

    The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw.

    “In Cellular Modem, there is a possible permission bypass due to a logic error in the code,” according to a description of the bug in the NIST National Vulnerability Database (NVD). “This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.”

    In an advisory issued Tuesday, Google acknowledged that it has found indications that “CVE-2026-58704 may be under limited, targeted exploitation” but stopped short of sharing any further details surrounding the nature of the attacks exploiting it, as well as the identity of the threat actor behind them.

    Cybersecurity

    Besides CVE-2026-58704, Google has addressed 109 other security flaws as part of the latest Pixel updates for September 2026. Of these, 88 allow privilege escalation, 10 allow information disclosure, nine allow remote code execution, and two allow denial-of-service (DoS).

    These include two high-severity privilege escalation vulnerabilities in Kernel components (CVE-2026-56914 and CVE-2026-58773), as well as 46 critical-severity vulnerabilities in various Pixel components, such as BigOcean, Bootloader, IP Multimedia Subsystem, and Trusted Execution Environment, that could lead to privilege escalation and remote code execution.

    Security patch levels of 2026-09-05 or later resolve all the identified flaws. Users are advised to update their devices to the latest version by navigating to Settings > Security & privacy.

    Back in June 2026, Google shipped patches for a high-severity flaw in Android’s Framework component (CVE-2025-48595, CVSS score: 8.4) that it said came under active exploitation.

    Update

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026, added CVE-2026-58704 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 19, 2026.

    “Google Pixel devices contain an improper authorization vulnerability in the cellular modem,” CISA said. “A logic error may allow an attacker to bypass permission checks and escalate privileges.”

    The vulnerability can be exploited as part of what’s called a zero-click attack, as it does not require a victim to click on a link or open a file to trigger the exploit. In other words, it can be exploited silently and without any interaction from the Pixel device owner.

    exploitation Flaw Google limited Modem Patches Pixel signs targeted
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

    Microsoft shares workaround for Windows domain login issues

    Google Research Introduces Retrieve-for-Train (R4T): An RL-Compiled Diffusion Retriever for 12× to 20× Faster Query Fan-Out

    Chinese hackers use SparroWocky malware in govt espionage attacks

    16 governance tools for securing your AI fleet

    NASA’s New Horizons spots signs of liquid nitrogen flowing on Pluto

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    One dead after torrential rain and flash floods hit Barcelona region

    September 17, 2026

    Apple Watch Series 12 Review: Finally, a Readiness Score (2026)

    September 17, 2026

    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    September 17, 2026

    SEC rolls out ‘innovation exemption’ for tokenized securities trading venues

    September 17, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    One dead after torrential rain and flash floods hit Barcelona region

    September 17, 2026

    Apple Watch Series 12 Review: Finally, a Readiness Score (2026)

    September 17, 2026

    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.