started · updated
Google patches critical Pixel modem flaw used in targeted attacks
Google has released an urgent security update for Pixel smartphones to address a high-severity vulnerability in the cellular modem, identified as CVE-2026-58704. The company has disclosed that there are indications the flaw may be under “limited, targeted exploitation.”
The vulnerability is a zero-click privilege escalation bug caused by a logic error in the modem's code. It allows an attacker in close proximity or on an adjacent network to bypass security sandboxes and gain unauthorized access to device data without any user interaction, such as clicking a link or opening a file.
In addition to this critical modem flaw, the September 2026 Pixel update addresses approximately 109 other vulnerabilities. These include various issues related to remote code execution, information disclosure, and further privilege escalations across components like the bootloader, Bluetooth, and the kernel.
Google recommends that all supported Pixel users, ranging from the Pixel 6 to the Pixel 11 Pro Fold, immediately install the update via their device settings to reach the September 5, 2026, security patch level.