Pixel Devices Fixed in September Update Amid Targeted Exploit Concerns
Google has released its September Pixel Drop update, which patches a critical security vulnerability in the cellular modem of certain Pixel devices. The flaw, identified as CVE-2026-58704, could allow an attacker to bypass permission checks and escalate privileges without requiring any user interaction.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities list, indicating that it may have been used in limited, targeted attacks. The CISA description of the flaw states that it is an 'improper authorization vulnerability' in the cellular modem, which could allow an attacker to bypass permission checks and escalate privileges.
Google has also patched 109 other security flaws in the update, including several high-severity vulnerabilities. To ensure protection from this vulnerability, Pixel users should update their devices to the latest September 5, 2026, security patch as soon as possible.