Google has released its September 2026 security update for Pixel devices, addressing 110 vulnerabilities. The patches include a high-severity Android zero-day that attackers may already be exploiting in limited, targeted operations.
The company is urging all owners of supported Pixel devices to install the update as soon as it becomes available.
Pixel Zero-Day Affects Cellular Modem
The actively exploited vulnerability is tracked as CVE-2026-58704. It affects the cellular modem component in Google Pixel devices.
Google attributed the flaw to a logic error that creates a permission bypass. The underlying weaknesses involve improper authorisation and the failure of a protection mechanism.
Successful exploitation can allow an attacker to escalate their privileges on a vulnerable smartphone.
However, the attacker needs access to an adjacent network and basic privileges on the targeted device. The attack has low complexity and does not require interaction from the user.
Google described the vulnerability as a remote or proximal escalation-of-privilege issue. Attackers do not need additional execution privileges to exploit the flaw.
Google Detects Limited Targeted Exploitation
Google said it had found indications that attackers may be exploiting CVE-2026-58704.
The company described the activity as limited and targeted. This wording often indicates that attackers are using a vulnerability against a small number of selected individuals rather than conducting widespread attacks.
However, Google did not identify the attackers or disclose who they targeted. It also provided no information about the broader attack chain.
Security flaws used in targeted mobile attacks often work alongside other vulnerabilities. One flaw may provide initial access, while another increases the attacker’s permissions or escapes a protected environment.
Google has not confirmed whether CVE-2026-58704 formed part of such a chain.
September Update Fixes 110 Vulnerabilities
The September Pixel security bulletin addresses 109 additional security problems alongside the actively exploited zero-day.
The update includes fixes for 12 remote code execution vulnerabilities. These flaws can potentially allow attackers to run malicious code on an affected device.
Google also patched 89 privilege escalation vulnerabilities rated critical or high severity. Such flaws can allow malicious applications or attackers with limited access to gain more control over a smartphone.
The remaining fixes address other weaknesses across Pixel hardware and software components.
All supported Google devices will receive the September 5, 2026, security patch level.
Pixel Devices Receive Separate Security Updates
Pixel smartphones use Android but receive security patches separately from devices made by other manufacturers.
Google controls the hardware platform and develops exclusive features for its Pixel range. Therefore, the company distributes additional fixes that address components and functions specific to those devices.
Other Android manufacturers release their own updates based on their hardware, software and support schedules.
Consequently, a patch available for Pixel devices may not appear on another manufacturer’s smartphone. At the same time, some security problems may affect only Google’s hardware.
How to Install the Pixel Security Update
Pixel users should install the September security update without delay.
To check for the update, users can open Settings, select Security & privacy, and then open System & updates. They should choose Security update and tap Install when the patch appears.
The device must restart to complete the installation.
Users should also verify the installed security patch level after the restart. The updated device should display the September 5, 2026, patch level.
The update may arrive at different times depending on the device model, mobile carrier and region. Users should check again later if it is not immediately available.
Google Patched Another Zero-Day in June
The September update follows another actively exploited Android vulnerability that Google addressed in June.
That flaw, tracked as CVE-2025-48595, affected the Android Framework. Attackers could use it to execute code and increase their privileges on devices running Android 14 or later.
Google also described that activity as targeted exploitation.
The two incidents demonstrate why users should install monthly Android and Pixel updates promptly. Targeted vulnerabilities may affect relatively few people at first, but technical details can eventually enable wider attacks.
Pixel Owners Should Update Immediately
Google has not published details about the attacks involving CVE-2026-58704. Nevertheless, confirmed signs of exploitation make the update urgent.
Users should also install application updates and remove apps they no longer need. Downloading software only from trusted sources can further reduce the risk of malicious applications gaining the basic access required for an exploit chain.
Organisations that manage Pixel devices should confirm that employees have installed the new patch. Mobile device management tools can help security teams identify smartphones running outdated software.
The September update fixes many serious vulnerabilities beyond the Pixel zero-day. Therefore, installing it protects devices against a broader range of potential attacks.


0 responses to “Google Fixes Actively Exploited Pixel Zero-Day”