The record
Written from the 1 report below. Nothing here is unsourced.
- Google has patched a high-severity privilege escalation flaw, tracked as CVE-2026-58704, in the cellular modem of Pixel phones.
- The flaw allows attackers to escalate privileges remotely with no user interaction, meaning devices can be attacked without the owner clicking anything.
- Google has found indications that the flaw is under limited, targeted exploitation, but has not named the attacker or described the attacks.
- The September 2026 Pixel update also fixes 109 other security flaws, including 46 rated critical.
- Pixel users should update their devices to the 2026-09-05 security patch level or later to stay protected.
What to watch next
- Details on who is behind the targeted attacks and which devices or regions were affected
- Further advisories from CISA or other agencies on exploitation of the modem flaw
- Confirmation that Pixel devices have received the 2026-09-05 patch level via Settings > Security & privacy
Coverage1
1 report
English national1
All filed from India
Named United States · Pixel · CISA · Google · National Institute of Standards and Technology
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
