Skip to content
feed: live
>_0dayNews
google
● Breaking

Google Patches Pixel Modem Zero-Day Under Attack

Google's September 2026 Pixel update patches 110 vulnerabilities including CVE-2026-58704, a high-severity modem flaw already under active exploitation. CISA deadline is September 19.

Google Patches Pixel Modem Zero-Day Under Attack
Photo: mammela / Pixabay · Pixabay License
fuseMarisol "Fuse" Delgado·Published ·1 min read

Google shipped the September 2026 Pixel security update on September 15, addressing 110 vulnerabilities across Pixel devices. One of them, CVE-2026-58704, was already under active exploitation before the patches arrived.

The modem flaw

CVE-2026-58704 is an improper authorization vulnerability in the Pixel cellular modem. A logic error allows an attacker in radio adjacency to bypass permission checks and escalate privileges on the device. CVSS score is 8.8 (high). No user interaction is required; the attacker needs only to be in the same network or radio environment as the target.

Google describes the flaw as a “possible permission bypass due to a logic error in the code” that could lead to “remote (proximal/adjacent) escalation of privilege.” That means this is not a remote internet attack: the threat model is an attacker within physical proximity, such as on the same cellular infrastructure or radio range.

CISA added CVE-2026-58704 to the Known Exploited Vulnerabilities catalog on September 16, 2026. Under BOD 26-04, federal agencies must remediate by September 19.

What to do

Update your Pixel device now:

  1. Go to Settings > Security & privacy > System & updates.
  2. Confirm the September 2026 security patch level is applied.
  3. Install any pending update.

For organizations managing Pixel fleets, the September 19 CISA deadline is a floor. With a CVSS 8.8 flaw confirmed under exploitation, waiting until a normal patch window closes is not justified. The Google Pixel update bulletin lists all addressed CVEs and affected models.

The broader September update

The September 2026 Pixel update fixes 109 additional vulnerabilities beyond CVE-2026-58704. Google’s Android Security Bulletin, published the same day, covers the overlapping set of fixes also pushed to non-Pixel Android devices. The modem zero-day is specific to the Pixel bulletin.

Previous KEV additions this month include RouterOS and ScreenConnect deadlines from September 13 and Cisco, Citrix, and Fortinet from September 11. The cadence is consistent: patch the KEV items before anything else on your list.

Related CVEs
  • [ HIGH ]CVE-2026-58704Google Pixel Cellular Modem Improper Authorization

Found this useful? Share it.