← BACK TO FEED
Google PixelCVEzero-click exploitCISAmobile security

Google Quietly Patches Exploited Pixel Modem Flaw — No Click Required

Google has patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem, which has been found under limited, targeted exploitation in the wild. The vulnerability stems from a logic error that allows remote attackers to bypass permissions without any user interaction, making it exploitable as a silent zero-click attack. The fix is included in the September 2026 Pixel security update, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by September 19, 2026.

Google has confirmed active exploitation of a high-severity vulnerability in the Pixel Cellular Modem, tucked into its September 2026 security update with minimal fanfare and even fewer details about who's being targeted.

The flaw, CVE-2026-58704, scores an 8.0 on the CVSS scale and stems from a logic error that allows privilege escalation via the modem component. No user interaction required. No additional privileges needed on the attacker's end. Just proximity, and apparently that's enough.

According to CISA, which added the vulnerability to its Known Exploited Vulnerabilities catalog on September 16th, this qualifies as a zero-click attack. The victim doesn't need to tap anything, open anything, or do anything at all. The exploit can run silently while the device sits in someone's pocket. CISA gave federal agencies until September 19th to patch — a notably tight three-day window that suggests someone, somewhere, is taking this seriously.

Google's own advisory acknowledged "limited, targeted exploitation" of the flaw, which is the standard phrasing companies use when they know attacks are happening but aren't ready, or willing, to say who's behind them. No threat actor named. No attack chain described. Just the bare minimum disclosure.

The modem patch wasn't travelling alone. Google's September Pixel update addresses 110 vulnerabilities in total. Of those, 88 involve privilege escalation, nine enable remote code execution, ten leak information, and two can cause denial of service. Forty-six are rated critical severity, touching components including the Bootloader, Trusted Execution Environment, and IP Multimedia Subsystem — not exactly low-stakes areas of the device.

Two high-severity kernel flaws, CVE-2026-56914 and CVE-2026-58773, also made the list.

Devices running security patch level 2026-09-05 or later are covered. If your Pixel hasn't prompted you to update, go find it under Settings > Security & privacy.

This follows a pattern. Back in June, Google patched another actively exploited high-severity flaw, that time in Android's Framework component. Targeted modem exploits showing up on consumer hardware with zero interaction required is the kind of thing that should probably prompt more than a footnote in a monthly bulletin — but here we are.

READ NEXT
CISA's Vulnerability Report Is a Masterclass in Déjà VuOpenAI's Own Systems Were Compromised by Its Own Agents100+ Water Systems Hit in July Cyberattacks — CISA Finally Puts a Number On It