A Pixel bug that needs no click just got a 3 day federal deadline
Key takeaways
- CVE-2026-58704 is an improper authorisation flaw in the Pixel cellular modem, CVSS 8.0, and requires no user interaction at all.
- CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September with a 19 September deadline for federal civilian agencies.
- Pixel 6 through Pixel 11, plus the Pixel Tablet and Pixel Fold, are affected. Any security patch level before 2026-09-05 is vulnerable.
Three days. That is how long CISA gave federal civilian agencies to patch CVE-2026-58704, and the shortness of that window is the most informative detail in the advisory.
What the flaw is
CVE-2026-58704 is an improper authorisation flaw in the cellular modem on Google Pixel devices, rated CVSS 8.0. The important part is that it is zero click. There is no link to tap, no file to open and no interaction of any kind. An attacker on an adjacent network, holding basic privileges on the device, can escalate quietly.
CISA added it to the Known Exploited Vulnerabilities catalogue on 16 September and set the remediation deadline at 19 September. Google has confirmed indications of limited, targeted exploitation.
Whether you are affected
Everything from the Pixel 6 series through the Pixel 11 family is affected, along with the Pixel Tablet and the Pixel Fold.
The check takes about ninety seconds. Open Settings, then About phone, then Android version, then Android security update. If your security patch level reads anything earlier than 2026-09-05, you are vulnerable. If the September patch has not reached your device yet, check again rather than assuming, because Pixel rollouts are staged and the modem firmware component does not always land with the main OS image.
Why a three day deadline is the signal
CISA deadlines normally run two to three weeks. Three days sits at the shortest end of what the agency issues, and it is not a judgement about how many devices are affected. It is a judgement about who is being targeted.
Zero click modem bugs are commercial spyware tradecraft, not opportunistic crime. They are expensive to develop, they burn the moment they go public, and they get spent on specific people. The targeting pattern Google described and the speed of the CISA deadline point the same direction.
That is a different risk profile from the Cisco email gateway flaw or the Parallels ParaShells escalation, where scanning and mass exploitation follow disclosure within hours. Here the exploit was already in use before anyone published a CVE.
What to watch
Most people reading this are not the target of a commercial spyware operation. The patch still takes ninety seconds, and the exposure window for a zero click closes the moment you apply it.
The thing worth tracking is whether the modem component shows up again. Baseband code sits below the operating system's security model, which is the same structural problem behind hypervisor escapes like Januscape: when the layer underneath is compromised, the protections above it do not get a vote.