Cyber Threat Intel 5 min read

A Pixel Modem Flaw Needs No Tap, and CISA Gave Three Days

The modem is a separate computer that answers to the mobile network, not to you. Nothing has to be opened, clicked or downloaded for this one to reach it.

Priya Nair
Data, AI Governance & Policy Analyst
Published 19 Sep 2026, 3:05 PM (SGT)
Share:
A red and white telecommunications mast carrying cellular antennas against a blue sky A red and white telecommunications mast carrying cellular antennas against a blue sky Photo by Ruttinan on Pixabay
Advertisement

19 SEP 2026 — A flaw in the cellular modem inside Google Pixel phones can be exploited without the owner touching anything, and federal agencies in the United States had until today to patch it.

Google says the vulnerability "may be under limited, targeted exploitation." That hedged wording is the strongest claim the company has made.

What the flaw does

CVE-2026-58704 is a permission bypass caused by a logic error in modem code, scored at 8.0. It allows an attacker who is nearby on the network to escalate privileges without needing any execution rights of their own.

The delivery is the part that matters. Reaching the modem requires nothing from the owner, so there is no link to avoid and no attachment to refuse. The Hacker News reported that it can be triggered silently and without any interaction from the device owner.

The fix is in the security patch level dated 5 September 2026 or later, reachable under Settings, then Security and privacy. The same bulletin closes 110 flaws in total, 46 of them rated critical, across components including the bootloader, the IP multimedia subsystem and the trusted execution environment.

Three days from listing to deadline

CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 16 September and set a federal remediation deadline of 19 September. Three days is short even for a catalogue built for urgency.

That interval is the agency's own judgement of how quickly this one matters. It is the clearest signal available about the seriousness of the exploitation, because Google has not described it beyond one hedged sentence.

8.0CVSS score
Zero-clickNo owner action required
3 daysKEV listing to federal deadline
110Flaws in the same bulletin, 46 critical

Why the modem is hard to defend

The cellular modem is a separate computer from the phone's main processor. It runs its own firmware and answers to the mobile network, not the operating system. A flaw there can be reached without the user ever unlocking the screen.

That separation is also why patching is awkward. Modem firmware updates travel through the device vendor rather than the operating system's usual channels, and a device that has stopped receiving vendor updates cannot be fixed by anything the owner does.

For Pixel devices the path is comparatively short, because Google makes both the phone and the update. Across the wider Android estate the same class of flaw takes considerably longer to reach users, because updates must pass from chipset vendor to handset maker to carrier.

What is not known

No actor has been named, no victim has been named, and no date has been given for when exploitation began. The word "targeted" usually indicates a specific list rather than opportunistic scanning, and a zero-click modem bug is expensive enough to build that it is rarely spent widely.

Advertisement

Neither reading is confirmed. Attribution on this class of flaw normally arrives later, from whoever handles the incident response, and the absence of detail this week means nothing either way.

Nor has Google credited a researcher. That is unusual enough to notice. Discovery credit is standard practice in Android bulletins, and its absence here is consistent with a flaw found through incident response rather than through a disclosure programme, though the company has not said so.

What owners should check

Open Settings, then Security and privacy, and confirm the security patch level reads 5 September 2026 or later. That single date covers this flaw and the other 109.

The federal deadline has passed as of today. That tells you what CISA thought of the risk but does nothing for anyone outside those agencies. Consumer devices update on their owners' schedules. A phone that has not been opened this week is still exposed.

The next question is whether this flaw reaches the wider Android estate. The flaw is in modem code, and modem code is rarely unique to one handset maker, so the question is whether other vendors ship the same component and how long their update chains take.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement