News

Pixel Modem Zero-Day CVE-2026-58704 Is Being Exploited: Patch Level 2026-09-05 Fixes It

Aditya Singh
Advertisement

Google has confirmed that a flaw in the Pixel's cellular modem, tracked as CVE-2026-58704, "may be under limited, targeted exploitation", and the fix ships in security patch level 2026-09-05. On 16 September the US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities catalogue and gave federal agencies until 19 September to patch.

For Pixel owners anywhere in the world, the practical answer is the same: if your phone's security patch level reads 2026-09-05 or later, you are protected against this bug. If it does not, install the September update now.

A black Google Pixel 8 Pro and a Pixel 9 Pro lying face down on a white table
Pixel phones from several generations receive the September 2026 patch that closes the exploited modem flaw. Image: Pixel 9 & Pixel 9 Pro Hands-On Impressions (ShoAndTech) (2160p 24fps VP9 LQ-160kbit Opus)-00.00.24.400 by ShoAndTech, via Wikimedia Commons (CC BY 3.0)
Advertisement

What the bug does

Google's September 2026 Pixel Update Bulletin, published on 15 September, lists CVE-2026-58704 under the Modem component as an elevation-of-privilege (EoP) issue rated High. The underlying cause is a logic error that lets an attacker skip a permission check.

Two details make it more serious than the rating suggests. The attack is proximal or adjacent, meaning it comes over the radio link from someone nearby or on the same network rather than through an app you install. And no user interaction is needed, so there is nothing to tap or open. That is the profile of a zero-click exploit.

CISA describes it as an improper authorization vulnerability in the Pixel's cellular modem and has flagged it for forensic triage, which means agencies are told to check devices for signs of past compromise, not only to patch them.

Who was targeted

Google has not said which Pixel models were attacked, who was behind it, or how many people were affected. "Limited, targeted" is the wording Google typically uses for attacks aimed at specific individuals, such as journalists, activists or officials, rather than a mass campaign. Nobody should read it as a sign that ordinary Pixel owners are being hit at scale.

The bulletin also does not specify which modem generations carry the flaw. Pixel phones have used different modem suppliers over the years, including a switch to MediaTek on the Pixel 11 series, so the safest assumption is that every supported Pixel needs the patch.

Which Pixels get the fix

The fix arrives with the Android 17 September release that Google began rolling out on 15 September (build CP3A.260905.009 for most devices). It is listed for:

  • Pixel 6, 6 Pro and 6a
  • Pixel 7, 7 Pro, 7a, Pixel Tablet and Pixel Fold
  • Pixel 8, 8 Pro and 8a
  • Pixel 9, 9 Pro, 9 Pro XL, 9 Pro Fold and 9a
  • Pixel 10, 10 Pro, 10 Pro XL and 10a
  • Pixel 11, 11 Pro, 11 Pro XL and 11 Pro Fold

The same release fixes around 20 Pixel-specific bugs, from Bluetooth drops to disappearing widgets, on top of the security work. Carrier-locked phones can lag the unlocked builds by a few days, so availability varies by region and operator.

Pixel 11 owners who installed the earlier September B1 maintenance build should still check the patch level string rather than assume they are covered, because the exploitation fix is tied to 2026-09-05 specifically.

How to check and update

  • Open Settings > Security & privacy > System & updates.
  • Look at Security update. The date shown must be 5 September 2026 or later.
  • If it is older, go to System update and tap Check for update, then restart when prompted.

Phones outside Google's support window, such as the Pixel 5 and older, will not receive this patch. Anyone still using one of those models as a daily phone has no fix coming for this flaw.

Last month's release followed a similar pattern; our write-up of the August Pixel update covers what that build changed.

Frequently Asked Questions

What is CVE-2026-58704?

CVE-2026-58704 is a high-severity elevation-of-privilege flaw in the cellular modem of Google Pixel phones. A logic error lets a nearby attacker bypass a permission check without any action from the user. Google says it may be under limited, targeted exploitation.

Which security patch fixes the Pixel modem zero-day?

Security patch level 2026-09-05 or later fixes CVE-2026-58704. It ships in the September 2026 Android 17 update for Pixel phones, which began rolling out on 15 September 2026. You can confirm the patch level under Settings, Security & privacy, System & updates.

Is my Pixel phone affected by the modem exploit?

Google has not named the specific models that were attacked, so any supported Pixel without the 2026-09-05 patch should be treated as exposed. That covers the Pixel 6 series through the Pixel 11 series, plus the Pixel Fold and Pixel Tablet. The attacks were described as limited and targeted rather than widespread.

Do I need to click anything to be hacked by this Pixel bug?

No. The bulletin says no user interaction is needed, and the attack comes from a nearby or adjacent network position rather than a malicious app. That is why installing the patch matters more than usual.

What is the CISA deadline for CVE-2026-58704?

CISA added CVE-2026-58704 to its Known Exploited Vulnerabilities catalogue on 16 September 2026 and set a remediation deadline of 19 September 2026. The deadline binds US federal agencies, but it is a strong signal for everyone else to update promptly.

Google PixelSecuritySoftware UpdateGoogleTech News

Related Articles

Advertisement