High 8.8 Actively Exploited

Cellular Modem permission bypass, exploited (CVE-2026-58704)

CVE-2026-58704

By Yazoul AI · automated

CVE-2026-58704: Cellular Modem adjacent-network permission bypass, actively exploited (CVSS 8.8). Apply the vendor fix without delay; no user interaction needed.

Affected: Google Android

Actively exploited in the wild - CVE-2026-58704 is a high-severity permission bypass in the Cellular Modem component that lets an attacker on the adjacent network escalate privileges remotely with no credentials and no user interaction. Because exploitation is confirmed, treat any device carrying this modem as exposed until the vendor fix is applied.

Overview

CVE-2026-58704 is a logic error in the Cellular Modem code that allows an attacker to bypass permission checks. The flaw carries a CVSS score of 8.8 and is rated HIGH.

The attack vector is adjacent network, meaning the attacker must be within radio or short-range network reach of the target, for example on the same cellular segment, a nearby base station link, or an attacker-controlled small cell. No authentication is required, no privileges are needed, and the victim does not have to click, open, or approve anything. The attack complexity is low, so a working exploit does not require special conditions or timing.

The root cause is a logic error, not a memory-safety bug. The code makes an incorrect decision about whether the caller is permitted to perform an action, and that decision can be influenced from the adjacent network. Because the defect is in an authorization path rather than a crash or corruption path, it can be triggered reliably and repeatedly.

Impact

Successful exploitation gives the attacker escalated privileges inside the modem and, depending on the platform, the broader device. That can mean access to modem control functions, the ability to observe or manipulate traffic, and a foothold that reaches further into the host system. Because no user interaction is required, the attack can proceed silently against devices that are simply powered on and connected.

Devices with this modem in range of a hostile transmitter or rogue cell are the primary exposure. This includes handsets, laptops with integrated cellular modules, IoT gateways, vehicles, and industrial equipment. Where the modem shares a bus or memory region with the main processor, the blast radius extends past the modem itself.

Remediation and Mitigation

Apply the vendor firmware update for the Cellular Modem as soon as it is available. Because this is confirmed exploited in the wild, patching should be prioritized over routine maintenance. Track the vendor advisory for the exact fixed build for each modem model.

If a fix is not yet available for your hardware, reduce exposure:

  • Disable cellular data or power off the modem when it is not in use.
  • Avoid operating the device near untrusted or unverified cellular infrastructure.
  • Enable any modem isolation or sandboxing feature the platform offers.
  • Monitor for unexpected privilege changes, modem resets, or anomalous traffic from the device.
  • Segment IoT and industrial endpoints that use cellular backhaul away from sensitive networks.

Incident responders tracking this campaign can find related coverage in our breach reports and security news sections.

Security Insight

Modem firmware has quietly become one of the least audited attack surfaces in modern computing: it sits below the operating system, often runs on a separate processor, and rarely receives the same patch cadence as application software. A logic error in an authorization path is a telling failure mode, because it suggests the code was never exercised against an adversarial caller in the first place. Adjacent-network escalation in baseband silicon echoes long-standing research into cellular stacks, and it reinforces that the modem should be treated as an untrusted peripheral rather than a trusted component of the device.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Other Google Android Vulnerabilities

View all Google Android vulnerabilities →

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.