CISA Flags Actively Exploited Google Pixel Vulnerability
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-58704, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects Google Pixel devices and is classed as an improper authorization issue, meaning attackers may be able to bypass access controls and gain unauthorised control of affected devices. CISA confirmed there is evidence of active exploitation in the wild.
While this directive formally applies to US federal agencies, which are required to patch listed vulnerabilities quickly under Binding Operational Directive 26-04, CISA encourages all organisations to treat KEV listings as a priority patching signal. Vulnerabilities that grant attackers full control of a device after exploitation pose particularly high risk, especially for businesses that rely on Android or Pixel devices for work email, authentication apps, or remote access.
Australian small businesses using Pixel devices, or Android devices generally, should check for and apply the latest security updates as soon as they are available and review mobile device management policies to ensure timely patching across staff devices.