GOOGLE has released its September 2026 Pixel security update, fixing a high-severity cellular modem vulnerability tracked as CVE-2026-58704, which has been exploited in limited, targeted attacks. The flaw has a CVSS score of 8.0 and is caused by a logic error that permits a permission bypass and elevation of privilege. Google’s advisory says exploitation requires no user interaction or additional execution privileges, but the attack is classified as remote, proximal or adjacent rather than broadly Internet-facing.
Google has not disclosed who exploited the vulnerability, how many devices were targeted or what the attacks were intended to achieve. It has also not attributed the activity to a commercial spyware provider or state-sponsored group, and has not published the complete attack chain. The issue affects the cellular modem, a security-sensitive component handling communications with mobile networks.
Google’s September Pixel bulletin addresses additional flaws across components including the kernel, bootloader, telephony stack, Trusted Execution Environment, GPU, Bluetooth and NFC. Supported Pixel devices using security patch level 2026-09-05 or later are protected against the issues covered by the Pixel and September Android bulletins.