Overview
- Google released the September 2026 Pixel security update Wednesday that fixes CVE-2026-58704 along with 109 other vulnerabilities and began rolling the patch to supported devices.
- The flaw is a logic-error permission bypass in the cellular modem that can enable remote privilege escalation without user interaction, meaning an attacker could gain higher access below Android’s app-layer protections.
- Available information says exploitation is limited and targeted and that a nearby or adjacent network position plus a basic foothold on a device are required rather than a broad internet-wide attack.
- CISA added the vulnerability to its Known Exploited Vulnerabilities list and Google and security outlets urged Pixel users and fleet managers to install the 2026-09-05 patch level immediately to close the hole.
- Google has not disclosed who carried out the attacks or how many devices were affected, and the incident highlights that modem-level bugs are attractive for targeted surveillance and pose special risks to high-value and enterprise users.