Google has patched a security flaw in Pixel phones that it says may be under limited, targeted exploitation. The US Cybersecurity and Infrastructure Security Agency added the modem vulnerability to its known exploited vulnerabilities catalog on September 16, bringing fresh urgency to the September security update.
CISA identifies the flaw as CVE-2026-58704 and lists September 19 as the remediation due date in its entry. The agency directs affected organizations to follow the vendor's mitigation instructions. Its catalog records use in ransomware campaigns as unknown, so the listing does not establish a connection to such attacks.
Google's description in the public CVE record says a logic error in the cellular modem can bypass permission checks. An attacker in network proximity could gain higher privileges without user interaction or additional execution privileges. The Pixel bulletin rates the vulnerability as high severity; it does not describe a universal attack against every Android phone.
The bulletin, published on September 15, covers supported Pixel devices and supplements the wider Android security bulletin. Google says a security patch level of 2026-09-05 or later addresses all issues in both September bulletins on its devices. That date identifies the patch level, rather than the publication date of the Pixel announcement.
Google's advisory reports indications of targeted exploitation but does not identify the attackers, victims or number of affected phones. CISA's new entry likewise names no perpetrator. Those disclosures establish a security concern requiring attention, while leaving the scale and circumstances of the attacks publicly unspecified.
Google urges customers to accept the updates. Its support guidance says owners can check their Android security update under About phone and Android version in Settings, and look for available updates under System and Software updates. Pixel updates downloaded in the background become active after a restart; delivery schedules vary by device and mobile carrier.
Comments