Key facts
- Google patched a zero-day vulnerability in Pixel phones, tracked as CVE-2026-58704.
- The vulnerability was found in the modem component of Pixel smartphones.
Google has released a security update to fix a zero-day vulnerability in its Pixel smartphones that was actively exploited in limited, targeted attacks. The flaw, tracked as CVE-2026-58704, could allow attackers to gain elevated privileges on a device without user interaction. The company urges all users to apply the September 2026 security patch.

The exploitation of a zero-day vulnerability in Pixel phones poses a direct security risk to users, potentially exposing their personal data through sophisticated, undetectable attacks. The prompt patching by Google is crucial for mitigating further compromise.
Google has addressed a high-severity security flaw in its Pixel smartphones that was actively exploited in limited, targeted attacks. The vulnerability, identified as CVE-2026-58704, resides in the device's modem and could allow attackers to escalate privileges, gaining access to sensitive data without any user interaction.
Google disclosed the vulnerability in its September 15 Pixel Update Bulletin, stating there are "indications" that CVE-2026-58704 is under exploitation. The company has not revealed who discovered the flaw, when the attacks began, or who was targeted. The security bulletin notes that exploitation requires no user interaction or additional execution privileges, and can be performed by an attacker in a proximal or adjacent network position.
The fix is included in the September 2026 Pixel security update, bringing supported devices to the 2026-09-05 patch level. This update addresses a total of 110 vulnerabilities, including 12 critical remote code execution flaws and 89 critical or high severity privilege escalation vulnerabilities in various components. Google advises all users to install the update to ensure their devices are protected.