
Google has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks.
Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings supported devices to the 2026-09-05 security patch level.
Google disclosed the vulnerability in its September 15 Pixel Update Bulletin, warning that there are “indications” that CVE-2026-58704 is under limited exploitation. The company has not disclosed who discovered the flaw, when the attacks began, or who was targeted, and the associated Android bug report, A-484011314, remains private.
CVE-2026-58704 affects the cellular modem and stems from a logic error that can bypass permissions. Google classifies the issue as an elevation-of-privilege vulnerability and says exploitation requires no user interaction or additional execution privileges.
Google's Pixel line consists of the company's first-party Android smartphones and other mobile devices, for which Google directly supplies operating system, firmware, and security updates. Pixel-specific bulletins cover vulnerabilities in components such as modems, bootloaders, trusted execution environments, biometric firmware, and Google's Tensor-related hardware.
According to the vulnerability description, an attacker in a proximal or adjacent network position could potentially interact with the cellular modem in a way that triggers the faulty permission check. Successful exploitation could then allow operations at a privilege level that should normally be inaccessible to the attacker.
Exactly what modem privileges could be obtained, which cellular messages or interfaces are involved, and what subsequent actions are possible have not been publicly documented. The wording suggests exploitation takes place through the modem's externally reachable cellular attack surface rather than requiring a malicious app installed on the device.
The September update also fixes a large number of critical Pixel vulnerabilities, including:
- CVE-2026-55318 and CVE-2026-55343 — critical remote code execution flaws affecting the IP Multimedia Subsystem and libpixelimsmedia.
- CVE-2026-56920 — critical remote code execution vulnerability in the VPU.
- CVE-2026-56967 — critical remote code execution flaw in the modem.
- CVE-2026-58683 and CVE-2026-58710 — critical remote code execution issues affecting telephone-related components and BigOcean.
- Numerous critical elevation-of-privilege vulnerabilities in the bootloader, Trusted Execution Environment, GSA, Trusty, KeyMint, fingerprint trusted applications, and telephony components.
Google says all supported Pixel devices will receive the 2026-09-05 patch level, which addresses these Pixel-specific flaws and vulnerabilities covered by the September 2026 Android Security Bulletin.
Because CVE-2026-58704 may already be exploited and requires no victim interaction, Pixel owners should install the September security update as soon as it becomes available and verify that their device reports a security patch level of September 5, 2026.







Leave a Reply