GOOGLE’S 16 September 2026 Pixel Update Bulletin addresses three Android vulnerabilities, including CVE-2026-58704, which Google says may be undergoing limited, targeted exploitation. The flaw affects the cellular modem firmware and is rated 8.0 under CVSSv3. It is described as a permission-bypass issue caused by a logic error in the code, potentially allowing remote privilege escalation without prior access or user interaction.
According to the report, exploitation requires an attacker to be on an adjacent or nearby cellular network. Google has confirmed exploitation in the wild, but no public proof-of-concept code has been released. The bulletin also covers CVE-2026-55318, rated 8.8, and CVE-2026-56967, rated 8.0; both are listed as not exploited. The article says supported Pixel smartphones running firmware released before September 2026 are affected.
Pixel owners should install the update with security patch level 2026-09-05 or later. Updates can be checked manually under Settings > System > System update.