If your Pixel hasn’t installed the September 2026 security update, your phone’s modem may be vulnerable to an attack that requires no action from you at all. Google confirmed in its September security bulletin that a critical vulnerability in Pixel devices — CVE-2026-58704 — is being actively exploited in the wild. The US Cybersecurity and Infrastructure Security Agency has listed it as a known exploited vulnerability and told federal agencies to patch by September 19.
CVE-2026-58704 is a permission bypass flaw in the cellular modem. The vulnerability stems from a code logic error. Google’s description identifies it as a “zero-click” vulnerability — meaning an attacker can exploit it without the device owner tapping a link, opening a file, or doing anything. Exploitation occurs through the cellular network itself.
Google says the exploitation is “limited and targeted,” which means active attacks have been detected but are not widespread. This language typically indicates a sophisticated actor targeting specific individuals rather than mass exploitation. CISA’s decision to add the flaw to its Known Exploited Vulnerabilities catalog means federal agencies are required to patch within three days of the September 16 notice. CISA does not add vulnerabilities to that list without evidence of real-world exploitation.
If you own a Pixel phone and you have not applied the September 2026 security patch, your modem firmware is unprotected against a flaw that other people are currently using to compromise devices. “Limited and targeted” means it is not affecting millions of users — but it also means the attack is real and functioning. Delaying the update because exploitation sounds rare is the same reasoning that makes targeted attacks effective.
What Makes a Modem Flaw Different
Most well-known phone vulnerabilities exploit messaging apps, browsers, or operating system components. A modem vulnerability is different. The modem is the hardware that handles your cellular connection — separate from Android, operating at a lower level than the apps you install. Attacks through the modem do not require a Wi-Fi connection, a malicious app, or a suspicious link. They can arrive through the cellular signal your phone is already receiving.
Google’s September bulletin does not specify which Pixel models are affected. The absence of a model list, combined with the description of a platform-level modem flaw, suggests the vulnerability spans multiple hardware generations rather than being confined to one device. The safest assumption is that all unpatched Pixel phones are exposed until Google specifies otherwise.
To check your patch status: go to Settings → About phone → Android version → Android security patch level. If it shows 2026-09-05 or later, the September fix is installed. If you see an earlier date, apply the update through Settings → System → System update. The update may already be waiting for you without a notification.
Which Pixel phones need the September 2026 update? Google has not specified which models are affected by CVE-2026-58704. Until Google clarifies, treat all Pixel devices running a patch level before September 5, 2026 as potentially exposed and update immediately.
Google typically publishes its monthly updates to Pixel devices in waves, so some users may not see the September update until it rolls out to their specific device. Check for Google’s full September security bulletin for the complete list of patched vulnerabilities and update instructions. The CISA Known Exploited Vulnerabilities catalog also lists federal patch deadlines for reference.