Google Patches Pixel Modem Flaw Linked to Targeted Exploitation

Google has released its September 2026 security update for Pixel devices, addressing 110 vulnerabilities, including a modem flaw that may be under limited, targeted exploitation.

The September 2026 Pixel Update Bulletin, published September 15, identifies CVE-2026-58704 as a high-severity elevation-of-privilege vulnerability affecting the modem. Google said there are indications the flaw may be under limited, targeted exploitation.

Google has not disclosed details about the attacks, including who is being targeted or how the vulnerability is being exploited. The associated Android bug is also marked as non-public in the bulletin, limiting the technical information currently available.

An elevation-of-privilege vulnerability can allow an attacker to obtain permissions beyond those normally available to them. Exploitation requirements vary by vulnerability, and Google’s bulletin does not specify what level of access or user interaction it requires.

Update fixes 46 critical vulnerabilities

The Pixel bulletin contains 46 critical vulnerabilities, along with 63 high-severity issues and one rated moderate. The fixes cover a wide range of components, including the bootloader, modem, telephony software, trusted execution environments, graphics hardware, NFC and Bluetooth.

Six of the critical vulnerabilities are classified as remote code execution flaws. They affect the IP Multimedia Subsystem, libpixelimsmedia, the video processing unit, modem, telephone component and a component Google identifies as BigOcean. Remote code execution vulnerabilities can allow an attacker to run code on an affected system when the necessary exploitation conditions are met.

The bulletin also includes critical elevation-of-privilege vulnerabilities in components such as the bootloader, Trusted Execution Environment, KeyMint and fingerprint-related trusted applications. Other critical issues are classified as information disclosure or denial of service vulnerabilities.

These fixes are specific to supported Google devices and are in addition to vulnerabilities covered by the broader September 2026 Android Security Bulletin.

Google said the most severe vulnerability in the Android-wide bulletin is a critical flaw in the System component that could allow remote code execution without requiring additional execution privileges or user interaction.

A security patch level of September 5, 2026, or later addresses the vulnerabilities in both the Pixel bulletin and the September Android Security Bulletin, according to Google. All supported Google devices are scheduled to receive that patch level.

Google began rolling out the September Pixel update on September 15 to supported devices running Android 17. The company said deployment would continue in phases over the following week, with timing depending on the device and carrier.

Pixel owners can check for an available update by opening: Settings >> System >> Software updates.

The installed security patch level is available under: Settings >> About phone >> Android version.

Users should confirm that the Android security update shows September 5, 2026, or a later date. That patch level includes the fix for CVE-2026-58704 as well as the other Pixel-specific and Android vulnerabilities addressed in the September release.

Pixel devices install downloaded system updates in the background, but the update becomes active after the device is restarted.