www.malwarebytes.com 16 Sept 2026, 10:39 UTC

Google Patches Pixel Modem Flaw Exploited in Targeted Attacks

Google Patches Pixel Modem Flaw Exploited in Targeted Attacks
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

GOOGLE’S September 2026 Pixel Update Bulletin fixes 110 vulnerabilities, including CVE-2026-58704, which Google says may be under limited, targeted exploitation. The high-severity flaw is in the phones’ cellular modem and results from a logic error that can bypass permissions, potentially allowing remote escalation of privilege without additional execution privileges or user interaction.

The report does not describe a straightforward internet-based takeover. Available information indicates that exploitation requires access to an adjacent network and basic privileges on the targeted device, although it does not explain how an attacker obtains those privileges. The vulnerability could therefore be used as part of a wider attack chain, alongside a malicious app, stolen credentials, physical access or another exploit, to gain access to restricted functions or data. Google has not said that merely being within wireless range is sufficient.

Pixel owners should install the update through Settings > Security & privacy > System & updates > Security update, then restart the device. A phone showing the 2026-09-05 patch level, or later, is up to date. The fix is specific to Pixel devices and their affected modem component; users of other Android brands should check for their manufacturer’s latest security update.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline