Back to Feed
Zero-daySep 16, 2026

Google fixes actively exploited Android zero-day on Pixel devices

Google fixes actively exploited Android zero-day on Pixel devices.

Summary

Google has released September 2026 security patches for Pixel devices, addressing 110 vulnerabilities. Among them is a high-severity zero-day flaw (CVE-2026-58704) in the Modem subcomponent that is under limited, targeted exploitation, allowing for privilege escalation via improper authorization and protection mechanism failures. Successful exploitation requires adjacent network access and basic privileges, with low complexity and no user interaction needed.

Full text

Google fixes actively exploited Android zero-day on Pixel devices By Sergiu Gatlan September 16, 2026 03:00 AM 0 Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. "There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company warned on Wednesday. "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices." This high-severity security flaw stems from improper authorization and protection mechanism failure weaknesses affecting the Modem subcomponent. Successful exploitation can allow attackers with access to an adjacent network and basic privileges on the targeted device to escalate privileges in low-complexity attacks that don't require user interaction. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," a security advisory issued today says. "This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed." Google tagged 109 other security issues in this month's Pixel update bulletin, including 12 remote code execution and 89 privilege escalation vulnerabilities rated critical or high severity. Although Google Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches distributed to Android OEMs because of the unique hardware platform Google controls directly and its exclusive features and capabilities. To apply this month's security updates, Pixel users must go to Settings > Security & privacy > System & updates > Security update, tap Install, and restart their devices to complete the update process. You can find more information on the September 2026 updates for Pixel devices in the security bulletin for Google's smartphone range. In June, Google also addressed an Android Framework zero-day flaw (CVE-2025-48595) that was actively exploited in targeted attacks and could let attackers gain code execution and escalate privileges on devices running Android 14 or later. One month earlier, the company announced an overhaul of its Android and Chrome vulnerability rewards programs, scaling back payouts for flaws that are easier to find using artificial intelligence (AI) while offering bounties of up to $1.5 million for some Android exploits. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Sonicwall warns of new SMA1000 zero-day exploited in attacksCheck Point warns of SmartConsole zero-day exploited in attacksNew Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accessCISA: Windows Task Host flaw now exploited by ransomware gangsMicrosoft working on Defender patch for ShieldBreak zero-day

Indicators of Compromise

  • cve — CVE-2026-58704
  • cve — CVE-2025-48595

Entities

Pixel (product)Android (product)Google (vendor)