Google discloses a high-severity vulnerability in its Pixel Cellular Modem that is being exploited in the wild. The flaw is tracked as CVE-2026-58704 and is rated CVSS 8.0. It is described as a privilege-escalation issue caused by a logic error that can bypass permissions.

SecurityWeek reports that Google patches the vulnerability on September 15 after it is observed being used in targeted attacks. The Hacker News similarly notes signs of limited, targeted exploitation rather than widespread activity. While the outlets focus on timing and exploitation scope, they align on the same technical description of the bug and on the fact that Google releases fixes in response to observed real-world use. Neither source provides detailed information on specific targets, affected devices, or the attacker methods beyond the general privilege-escalation nature of the vulnerability.