Google Fixes Pixel Modem Flaw Exposed by Zero-Day Attacks
Google has confirmed that some Pixel phones have been targeted in zero-day attacks due to a flaw in the cellular modem. The vulnerability, known as CVE-2026-58704, allows an attacker to gain a higher level of access than most attacks and can occur without any user action or permission.
The CVSS severity score for this vulnerability is 8.0 out of 10, indicating its high risk. Google has fixed the issue in its September 2026 Pixel update, which began rolling out on Tuesday, September 15. The company hasn't shared how many Pixel devices or even which models it believes have been affected.
Pixel owners should update their phones as soon as possible to the September 2026 security patch through Settings > System > Software updates > System update. Devices with patch level 2026-09-05 or later can install the fix.