Google has patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem, which has been found under limited, targeted exploitation in the wild. The vulnerability stems from a logic error that allows remote attackers to bypass permissions without any user interaction, making it exploitable as a silent zero-click attack. The fix is included in the September 2026 Pixel security update, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by September 19, 2026.