Google patches actively exploited Pixel modem zero-day in targeted attacks
Google shipped its September 2026 Pixel security update on September 16, patching 110 vulnerabilities including one actively exploited zero-day tracked as CVE-2026-58704. The flaw sits in the Modem subcomponent used by Pixel devices and stems from a logic error that creates a permission bypass, according to Google's own advisory.
An attacker with access to an adjacent network and only basic privileges on the target device can exploit the bug to escalate permissions without any user interaction — no tap, no click, no social engineering required. Google says it has indications that CVE-2026-58704 “may be under limited, targeted exploitation,” language the company typically reserves for attacks it believes are being used against specific individuals rather than broadly distributed malware campaigns. Google did not disclose who is behind the exploitation or how many devices have been affected.
The update brings supported Pixel devices to the 2026-09-05 security patch level. Beyond the zero-day, the September patch addresses 12 bugs that could allow remote code execution and 89 rated critical or high severity for privilege escalation. Pixel owners can apply the fix by going to Settings, then Security & Privacy, then System & Updates, then Security Update, and restarting the device once the download completes.
This marks the second actively exploited Android zero-day Google has disclosed this year, following CVE-2025-48595 in June. Modem-level vulnerabilities are particularly prized by sophisticated attackers because they sit below the operating system's normal security boundary — a successful exploit can potentially intercept or manipulate cellular communications before app-layer protections ever get a chance to act, and the “adjacent network” access requirement means an attacker doesn't need physical possession of the device, only proximity to its cellular or radio environment.
As reported by BleepingComputer, security researchers have increasingly flagged baseband and modem firmware as an under-scrutinized layer of mobile security, since it typically runs proprietary code from chip vendors that receives far less independent auditing than the Android OS itself. Pixel users, particularly anyone who might be an individually targeted rather than opportunistic target, should apply the September update immediately rather than waiting for the next scheduled patch cycle.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source