Pixel Devices Hit with Critical Vulnerability as CISA Sets Remedy Deadline
A critical security vulnerability has been discovered in Google Pixel devices, allowing unauthorized attackers to bypass standard permission checks and escalate privileges directly at the baseband/modem component layer.
The flaw, identified as CVE-2026-58704, was patched by Google as part of its September 15, 2026 security release, addressing a logic error in the Pixel Cellular Modem component. The fix is delivered in security patch level 2026-09-05 or later across supported Google Pixel devices.
The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog and establishes a federal remediation deadline of September 19, 2026. While this mandate specifically targets U.S. federal agencies, it serves as an urgent benchmark for enterprise security teams to prioritize and enforce updates immediately across all mobile deployments.