Google Quietly Patches Exploited Pixel Modem Flaw — No Click Required
Google has confirmed active exploitation of a high-severity vulnerability in the Pixel Cellular Modem, tucked into its September 2026 security update with minimal fanfare and even fewer details about who's being targeted.
The flaw, CVE-2026-58704, scores an 8.0 on the CVSS scale and stems from a logic error that allows privilege escalation via the modem component. No user interaction required. No additional privileges needed on the attacker's end. Just proximity, and apparently that's enough.
According to CISA, which added the vulnerability to its Known Exploited Vulnerabilities catalog on September 16th, this qualifies as a zero-click attack. The victim doesn't need to tap anything, open anything, or do anything at all. The exploit can run silently while the device sits in someone's pocket. CISA gave federal agencies until September 19th to patch — a notably tight three-day window that suggests someone, somewhere, is taking this seriously.
Google's own advisory acknowledged "limited, targeted exploitation" of the flaw, which is the standard phrasing companies use when they know attacks are happening but aren't ready, or willing, to say who's behind them. No threat actor named. No attack chain described. Just the bare minimum disclosure.
The modem patch wasn't travelling alone. Google's September Pixel update addresses 110 vulnerabilities in total. Of those, 88 involve privilege escalation, nine enable remote code execution, ten leak information, and two can cause denial of service. Forty-six are rated critical severity, touching components including the Bootloader, Trusted Execution Environment, and IP Multimedia Subsystem — not exactly low-stakes areas of the device.
Two high-severity kernel flaws, CVE-2026-56914 and CVE-2026-58773, also made the list.
Devices running security patch level 2026-09-05 or later are covered. If your Pixel hasn't prompted you to update, go find it under Settings > Security & privacy.
This follows a pattern. Back in June, Google patched another actively exploited high-severity flaw, that time in Android's Framework component. Targeted modem exploits showing up on consumer hardware with zero interaction required is the kind of thing that should probably prompt more than a footnote in a monthly bulletin — but here we are.