Executive brief
Google Pixel smartphones contain an improper authorization vulnerability that allows attackers to gain unauthorized access to device functionality. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation in the wild, indicating attackers are actively using this flaw to compromise user devices. This vulnerability poses a significant risk to federal agencies and all organizations, as successful exploitation could grant an attacker complete control over the affected device.
Technical details
CVE-2026-58704 is an improper authorization vulnerability in Google Pixel devices that allows attackers to bypass authorization controls and gain unauthorized access to privileged functionality. The vulnerability has been added to CISA's KEV Catalog based on confirmed evidence of active exploitation by threat actors. As an improper authorization flaw, the vulnerability likely stems from insufficient access controls on sensitive device operations, potentially allowing an attacker to escalate privileges or access protected resources without proper authentication or authorization checks. Successful exploitation grants an attacker total control of the affected device post-compromise. Organizations and federal agencies are advised to prioritize patching this vulnerability on publicly exposed Pixel devices, with federal agencies required by BOD 26-04 to apply remediation rapidly. Google should issue security updates to address this authorization bypass.
Affected products
- Google Pixel <UNKNOWN>
Timeline
- 2026-09-16: kev added