Google Patches Active Zero-Day Flaw on Pixel Devices
Google has released its September 2026 security patches to address 110 vulnerabilities affecting Pixel devices, including one zero-day flaw that's being actively exploited in targeted attacks.
The high-severity security flaw, CVE-2026-58704, stems from improper authorization and protection mechanism failure weaknesses in the Modem subcomponent. This can allow attackers with access to an adjacent network and basic privileges on the device to escalate privileges in low-complexity attacks without user interaction.
Google warned that there are indications of limited, targeted exploitation of this flaw. The company has tagged 109 other security issues in this month's Pixel update bulletin, including 12 remote code execution and 89 privilege escalation vulnerabilities rated critical or high severity.