Google fixes actively exploited Android zero-day on Pixel devices
Google released September patches for Pixel, fixing 110 vulnerabilities, including zero-day CVE-2026-58704 in the modem, which is already used in targeted attacks. The flaw allows privilege escalation over an adjacent network without user interaction.
- September patch fixes 110 vulnerabilities in Pixel devices
- CVE-2026-58704 in modem exploited in targeted attacks
- 12 issues are remote code execution, 89 are privilege escalation
- Update to level 2026-09-05 via settings and reboot
Read next
Security