CVE-2026-58704 - Google Android Privilege Escalation Flaw


Lookout Coverage and Recommendation for Admins
To ensure your devices are protected, Lookout admins should take the following steps in their Lookout console:
- Configure Mobile OS Update Policies: Set the compliance threshold to Android Security Patch Level 2026-09-05 (or later) for Google Pixel devices to address CVE-2026-58704.
- Define Compliance Actions: Define whether non-compliant devices receive a warning or a total block from corporate data and applications until the update is confirmed.
- Establish Escalation Timelines: If your organization permits a grace period, configure the policy to automatically escalate in severity, increasing user restrictions over a short duration that aligns with your internal security protocols and the CISA KEV remediation schedule.
Overview
CISA and Google have flagged a serious security risk for Google Pixel users. CVE-2026-58704 is a high-severity zero-day vulnerability where a logic error within the cellular modem driver on Google Pixel devices leads to a permission bypass. An unauthorized attacker (or an adjacent actor, depending on the vector) can leverage this flaw to bypass standard permission checks and escalate privileges directly at the baseband/modem component layer. User interaction is not needed for exploitation.
Google officially patched this critical vulnerability (CVE-2026-58704) as part of its September 15, 2026 security release, addressing a permission bypass caused by a logic error in the Pixel Cellular Modem component. The fix is delivered in security patch level 2026-09-05 or later across supported Google Pixel devices. More details can be found in the following bulletin: https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
Following reports of active targeted exploitation, CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026, establishing a federal remediation deadline of September 19, 2026. While this mandate specifically targets U.S. federal agencies, it serves as an urgent benchmark for enterprise security teams to prioritize and enforce updates immediately across all mobile deployments.
Lookout Analysis
Software is rarely flawless, no matter who develops it. Security vulnerabilities are a reality across all enterprise technology, from desktop operating systems to mobile hardware components. While modern mobile security models provide strong sandboxing, low-level component flaws—such as baseband and driver logic errors—continue to bypass traditional OS permission controls.
This incident and similar zero-click exploits prove that despite extensive code audits and mitigation efforts, firmware- and driver-level vulnerabilities remain a persistent, practical threat to enterprise mobile fleets. Without comprehensive visibility into mobile risk, sensitive organization data remains exposed. To bridge this gap, security teams should utilize mobile EDR to integrate real-time device and application vulnerability telemetry directly into their SIEM, SOAR, or XDR ecosystem.
Authors


Lookout Mobile Endpoint Security
Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.
Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

