Affiliate links on Android Authority may earn us a commission. Learn more.
There's a serious security fix hiding in Google's September Pixel update
Sep 16, 2026 — 10:15 PM ET

- Google’s September Pixel security update patches a cellular modem vulnerability that may have been used in limited, targeted attacks.
- CVE-2026-58704 could allow a remote attacker to bypass permission checks and escalate privileges without requiring any interaction from the victim.
- CISA has added the flaw to its Known Exploited Vulnerabilities list.
Google just released the September Pixel Drop, alongside details of its monthly security fixes for Pixel devices. But amid all the new features that stable Android 17 QPR1 brings, one security flaw may have gone unnoticed. Google and other relevant authorities have now confirmed that a Pixel modem vulnerability, which has now been patched, was used in targeted exploitation.
Google’s September security bulletin for Pixel devices lists CVE-2026-58704 as a vulnerability that may have been used for “limited, targeted exploitation.” The flaw affects the cellular modem on Pixel phones, potentially leaving devices vulnerable to a zero-click attack. This type of attack requires no user interaction, meaning they don’t need to click anything or open a malicious file for the exploit to work.
It’s unclear which Pixel devices were affected by the vulnerability or how extensive the targeting was. However, the US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-58704 to its Known Exploited Vulnerabilities (KEV) list, describing the flaw as follows:
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
CISA now requires Federal Civilian Executive Branch (FCEB) agencies to apply the relevant fixes by September 19, 2026.
If you’re a Pixel user, you should update your device to the latest September 5, 2026, security patch to ensure you’re protected. Alongside this remote privilege escalation vulnerability, Google has also patched 109 other security flaws in the update, including several high-severity vulnerabilities.
Thank you for being part of our community. Read our Comment Policy before posting.