Google has pushed its September 2026 security update for Pixel devices, addressing 110 vulnerabilities across Android and Pixel-specific components. One of those patches stands out: CVE-2026-58704, a privilege-escalation zero-day that Google says shows “indications” of limited, targeted exploitation in the wild. The flaw is in Pixel’s modem firmware layer — an especially sensitive area because code at that level can bypass many of Android’s higher-level security controls. Google has not attributed the attacks or named affected victims, but the confirmation of active misuse makes this update time-sensitive.
Privilege escalation flaws in modem firmware can let malicious code — either a rogue app or an injected payload from another exploit — gain elevated access to device functions that are normally off-limits to unprivileged processes. Google is rolling the fix out as patch level 2026-09-05 to all supported Pixel models and is urging all customers to apply the update as soon as it is offered. The same bulletin covers 109 additional CVEs, including further privilege escalation issues and information-disclosure bugs.
How to check if you’re affected
Affected devices are all supported Google Pixel models running a build older than the September 2026 security patch level (2026-09-05). To check your current patch level, open Settings → About phone → Android version → Android security update. If the date shown predates September 2026, your device has not received the fix. Tap Check for update (or go to Settings → System → System update) to pull the patch immediately.
