Google Pixel Zero-Click Modem Flaw CVE-2026-58704 Under Active Exploitation—Patch by Sept 19

September 18, 2026
2 mins read
Google Pixel smartphone photographed against a plain background
A Google Pixel smartphone represents devices covered by monthly Android security updates, where modem-level flaws can require urgent patching. [Photo: Wikimedia Commons / Tatsuo Yamashita / CC BY 2.0]

If your Pixel hasn’t installed the September 2026 security update, your phone’s modem may be vulnerable to an attack that requires no action from you at all. Google confirmed in its September security bulletin that a critical vulnerability in Pixel devices — CVE-2026-58704 — is being actively exploited in the wild. The US Cybersecurity and Infrastructure Security Agency has listed it as a known exploited vulnerability and told federal agencies to patch by September 19.

CVE-2026-58704 is a permission bypass flaw in the cellular modem. The vulnerability stems from a code logic error. Google’s description identifies it as a “zero-click” vulnerability — meaning an attacker can exploit it without the device owner tapping a link, opening a file, or doing anything. Exploitation occurs through the cellular network itself.

Google says the exploitation is “limited and targeted,” which means active attacks have been detected but are not widespread. This language typically indicates a sophisticated actor targeting specific individuals rather than mass exploitation. CISA’s decision to add the flaw to its Known Exploited Vulnerabilities catalog means federal agencies are required to patch within three days of the September 16 notice. CISA does not add vulnerabilities to that list without evidence of real-world exploitation.

If you own a Pixel phone and you have not applied the September 2026 security patch, your modem firmware is unprotected against a flaw that other people are currently using to compromise devices. “Limited and targeted” means it is not affecting millions of users — but it also means the attack is real and functioning. Delaying the update because exploitation sounds rare is the same reasoning that makes targeted attacks effective.

What Makes a Modem Flaw Different

Most well-known phone vulnerabilities exploit messaging apps, browsers, or operating system components. A modem vulnerability is different. The modem is the hardware that handles your cellular connection — separate from Android, operating at a lower level than the apps you install. Attacks through the modem do not require a Wi-Fi connection, a malicious app, or a suspicious link. They can arrive through the cellular signal your phone is already receiving.

Google’s September bulletin does not specify which Pixel models are affected. The absence of a model list, combined with the description of a platform-level modem flaw, suggests the vulnerability spans multiple hardware generations rather than being confined to one device. The safest assumption is that all unpatched Pixel phones are exposed until Google specifies otherwise.

To check your patch status: go to Settings → About phone → Android version → Android security patch level. If it shows 2026-09-05 or later, the September fix is installed. If you see an earlier date, apply the update through Settings → System → System update. The update may already be waiting for you without a notification.

Which Pixel phones need the September 2026 update? Google has not specified which models are affected by CVE-2026-58704. Until Google clarifies, treat all Pixel devices running a patch level before September 5, 2026 as potentially exposed and update immediately.

Google typically publishes its monthly updates to Pixel devices in waves, so some users may not see the September update until it rolls out to their specific device. Check for Google’s full September security bulletin for the complete list of patched vulnerabilities and update instructions. The CISA Known Exploited Vulnerabilities catalog also lists federal patch deadlines for reference.

Rahul Somvanshi

Rahul, possessing a profound background in the creative industry, illuminates the unspoken, often confronting revelations and unpleasant subjects, navigating their complexities with a discerning eye. He perpetually questions, explores, and unveils the multifaceted impacts of change and transformation in our global landscape. As an experienced filmmaker and writer, he intricately delves into the realms of sustainability, design, flora and fauna, health, science and technology, mobility, and space, ceaselessly investigating the practical applications and transformative potentials of burgeoning developments.

Leave a Reply

Your email address will not be published.

Exterior of a Suffolk Police station building with scaffolding and parked cars nearby
Previous Story

Noah Woods search: Police confirm body recovered and formally identified in Brantham

Rows of students seated at desks in an examination hall
Next Story

NTA exam calendar 2027: JEE Main starts January 22 as testing agency sets next year’s schedule

Latest from Technology

Don't Miss

Exterior facade and classical marble columns of the Marriner S. Eccles Federal Reserve Board Building in Washington, D.C.

Federal Reserve raises rates to 3.75%-4% as inflation remains elevated

The Federal Reserve has raised its benchmark interest