Google patches a Pixel phone flaw that hackers are already using

September update fixes 110 bugs in Pixel devices, including a modem weakness attackers can hit from nearby without a tap from the owner.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial shot of a rack-mounted enterprise SD-WAN router in a dim data center aisle, status LEDs glowing amber and green, blue ambient lighting
Share

Key points

  • Google shipped its September 2026 Pixel security update on Wednesday, fixing 110 vulnerabilities.
  • One of them, CVE-2026-58704, is a modem flaw already being used in what Google calls limited, targeted attacks.
  • The bug lets a nearby attacker gain higher access on a Pixel with no action required from the owner.
  • The update also patches 12 remote code execution bugs and 89 privilege escalation bugs rated high or critical.
  • Pixel owners get the fix by opening Settings, then Security & privacy, then System & updates, then Security update.

Google has pushed out its September 2026 security patches for Pixel phones, and one of the holes was already being picked in the wild.

The headline bug is CVE-2026-58704, a flaw in the cellular modem, which is the chip inside your phone that talks to the mobile network. Google says there are "indications" it "may be under limited, targeted exploitation," the company's careful way of confirming real people are being attacked, just not many yet.

The other 109 fixes cover 12 remote code execution bugs (where an attacker runs their own code on your phone) and 89 privilege escalation bugs (where malicious code already on the device promotes itself to a level it was never meant to reach). Most are rated high or critical.

First reported by BleepingComputer, the update is live now for supported Pixels at patch level 2026-09-05.

What is the zero-day and who is at risk?

A zero-day is a flaw attackers found and used before the maker had a patch ready. This one lives in the modem and stems from a logic error that lets code bypass a permission check. A device near yours on the same network could gain elevated powers on your Pixel without you opening anything or touching the screen.

Google's advisory calls it a "remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed." Adjacent means the attacker must be close by in network terms, not operating from the other side of the world. That narrows the risk, but it also fits the profile of targeted spyware sold to governments, which is where most Pixel zero-days land.

We covered a similar no-interaction modem flaw on 17 August, when researchers showed a VoLTE video call could hand attackers full kernel access on Unisoc chips with no patch available at the time.

Should Pixel owners do anything today?

Yes. Install the update. On a Pixel, go to Settings, then Security & privacy, then System & updates, then Security update, tap Install, and let the phone restart.

Pixels get their own patches separately from other Android phones because Google controls the hardware directly. That's usually a speed advantage. Samsung, Xiaomi and other Android OEMs will wait longer for the underlying fixes to filter through their own update pipelines.

Item Detail
Patch level 2026-09-05
Total fixes 110
Actively exploited CVE-2026-58704 (modem)
Remote code execution bugs 12
Privilege escalation bugs 89

How does this fit the wider pattern?

This is the second exploited zero-day Google has patched on the Android side this year that reads like spyware plumbing. In June, the company fixed CVE-2025-48595 in the Android Framework, also tagged as used in targeted attacks, also a privilege escalation.

Here's the plain judgement: modem and baseband bugs are the quiet frontier. Attacks are narrow, victims tend to be journalists or government officials, and nothing shows up in consumer headlines. But when a bulletin marks a flaw "proximal, no user interaction," that's exactly the profile commercial spyware vendors pay for. Google adjusting its rewards program to offer up to $1.5 million for serious Android exploits while scaling back payouts for AI-found bugs tells you where the market pressure sits.

Patch the phone. Five minutes.

© 2026 Threat Vectr