Google has issued the September 2026 security update for Pixel smartphones to fix 110 security flaws, among them a zero-day vulnerability that is currently being exploited in limited, targeted attacks.
The zero-day, tracked as CVE-2026-58704, resides in the Modem subcomponent and stems from authorization and protection mechanism deficiencies. According to Google's security advisory released Wednesday, "There are indications that CVE-2026-58704 may be under limited, targeted exploitation."
The flaw allows attackers positioned on an adjacent network with basic device privileges to escalate their access through low-complexity attacks requiring no user interaction. The vulnerability description notes: "In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed."
The September patch batch includes 109 additional security issues across Pixel devices, with 12 rated as critical remote code execution flaws and 89 classified as critical or high-severity privilege escalation vulnerabilities.
Google stated: "All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices."
Pixel devices receive their own dedicated security updates separate from the standard Android monthly patches distributed to other manufacturers. This distinction exists because Google directly controls Pixel hardware and its proprietary features.
To install the update, Pixel users should navigate to Settings > Security & privacy > System & updates > Security update, select Install, and restart their device to complete the process.
This marks the second zero-day in Android components that Google has patched in recent months. In June, the company fixed CVE-2025-48595, an Android Framework zero-day under active exploitation that could enable code execution and privilege escalation on devices running Android 14 or later.
Earlier this year, Google restructured its Android and Chrome vulnerability reward programs, reducing payouts for vulnerabilities that are simpler to discover using artificial intelligence while introducing bounties reaching $1.5 million for certain Android exploits.