
Google released the September 2026 security updates for Pixel devices, addressing 110 vulnerabilities – including one zero-day vulnerability that is actively being exploited in targeted attacks.
"There are indications that the CVE-2026-58704 vulnerability may be used for limited, targeted purposes," the company warned on Wednesday. "All supported Google devices will receive the patch level update as of September 5, 2026. We recommend all users apply these updates on their devices."
The serious vulnerability arises from failures in authorization and protection mechanisms affecting the modem component. Successful exploitation could allow an attacker with access to a neighboring network and basic privileges on the target device to escalate their privileges through simple attacks that do not require user interaction. "In the Cellular Modem system, there is a possibility of bypassing permissions due to a logical error in the code," the security bulletin states. "This could lead to remote (nearby/mediated) privilege escalation without the need for additional execution rights."
In this month's Pixel update bulletin, Google highlighted 109 other security issues, including 12 vulnerabilities related to remote code execution and 89 privilege escalation vulnerabilities classified as critical or high severity. Although Pixel devices also run on Android, they receive separate security updates and bug fixes – due to the unique hardware platform that Google directly controls, as well as its exclusive features.





