GOOGLE has patched a high-severity zero-day in the modem component of Pixel smartphones after observing “limited, targeted exploitation”. Tracked as CVE-2026-58704, the vulnerability results from a logic error that can allow a permission bypass and remote escalation of privilege from an adjacent or nearby position. Exploitation requires no additional execution privileges or user interaction, making it a zero-click flaw. Google has not identified the threat actor or attackers responsible.
The latest Pixel updates also include the September 2026 Android security patches and fixes for more than 100 additional Pixel-specific vulnerabilities. Nearly 50 are rated critical and affect components including the multimedia subsystem, VPU, modem, telephone, bootloader, TEE, libpixelimsmedia, GDMC, GSA and GPCA. These issues can enable remote code execution or privilege escalation, while other high-severity flaws may allow information disclosure or denial of service. Pixel owners should install the latest available device update.