Google is warning Pixel owners about a serious security vulnerability in the cellular modem that the company says has already been identified in real-world attacks. The issue is rated high severity and is all the more important because it can be exploited without any user intervention.

The vulnerability is listed as CVE-2026-58704 and has a CVSS score of 8.0 . It is a privilege escalation flaw , meaning an error that could allow an attacker to gain higher privileges than they normally have on the system.
The problem lies in the Pixel's modem
The cellular modem is one of the most important subsystems of a modern smartphone. It is responsible for the device's communication with mobile networks and operates largely independently of the applications that the phone owner uses daily.
According to the vulnerability description in NIST's National Vulnerability Database, CVE-2026-58704 is due to a logic error in the code, which can lead to bypassing protection mechanisms and escalation of privileges.
Particularly worrying is the fact that the exploit does not require additional execution rights or user interaction. The attack can be carried out from close range or via a neighboring network, which significantly differentiates this scenario from a classic phishing attack, which usually requires the user to click on a link or open a malicious file.
See also: Google adds Rust-based DNS Parser to Pixel 10's Modem
Google confirms limited targeted attacks
The most important element of the case is that Google is not treating CVE-2026-58704 as a theoretical threat. The company says there is evidence of limited and targeted exploitation of the vulnerability.
Google, however, did not provide further information about the attacks. It is not known which users or organizations were targeted, what techniques were used, or which threat actor may be behind the campaign.
The limited nature of the exploit does not mean that the issue only affects a small number of users. On the contrary, when a vulnerability is known to be actively used, the risk of it being analyzed by more attackers and incorporated into new attack tools increases.

Over 100 fixes in the September Pixel update
CVE-2026-58704 isn't the only issue addressed in the new security update. Google fixed a total of 110 vulnerabilities in the September 2026 Pixel updates.
Of these, 88 are related to privilege escalation, while another 10 are related to information disclosure. At the same time, nine vulnerabilities were identified that could lead to remote code execution and two related to DoS attacks.
See also: Google Pixel 9 to be equipped with Samsung Exynos Modem 5400
Among the fixes are also two high-severity vulnerabilities in the Android Kernel, CVE-2026-56914 and CVE-2026-58773. In addition, the update includes dozens of critical vulnerabilities in individual components of the Pixel ecosystem, such as BigOcean, Bootloader, IP Multimedia Subsystem and Trusted Execution Environment.
The combination of these issues shows that the security of a smartphone does not depend solely on the Android operating system. Kernel, modem, bootloader and hardware-backed security mechanisms are equally important parts of the overall defense.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The update should be installed immediately
Google says that security updates dated September 5, 2026 or later fix these issues. For Pixel owners, installing the available security update is the most important step to protect yourself.
Users can check for new updates through Settings > Security & privacy and install the latest available version for their device.
It is also important not to ignore security updates because the phone is working normally. Many vulnerabilities do not show obvious symptoms to the user, while their exploitation can occur in the background.
It's not the first actively exploitable vulnerability
The disclosure comes just a few months after another incident. In June 2026, Google patched the high-severity vulnerability CVE-2025-48595, which affected the Android Framework and had a CVSS score of 8.4. At the time, the company reported that the issue was being actively exploited.
The recurrence of such incidents is a reminder that smartphones are now complex computers, with dozens of different subsystems and software layers. A weakness in one of them can create cascading risks for the entire device.
See also: Google Pixel 12 Pro Fold: Screen without creases

What users should keep in mind
The key message for Pixel owners is simple: should security updates n't be delayed, especially when a vulnerability has already been linked to real attacks. CVE-2026-58704 is yet another reminder that attackers are looking for ways to bypass defenses not just through apps and websites, but also at deeper levels of the device.
Keeping your Pixel on the latest available security version, along with installing apps from trusted sources and avoiding suspicious networks or connections, remains a key part of an effective protection strategy.
