Google Patches Actively Exploited Android Zero-Day in Pixel Security Update
Google releases its September 2026 security updates for Pixel devices, patching 110 vulnerabilities, including a high-severity zero-day flaw that is under active exploitation. The company warns that CVE-2026-58704 "may be under limited, targeted exploitation" and urges all customers to install the updates, which bring supported devices to the 2026-09-05 patch level.
The exploited flaw stems from improper authorization and a failed protection mechanism in the Modem subcomponent. A logic error in the cellular modem code enables a permission bypass that allows attackers on an adjacent network with basic privileges to escalate privileges in low-complexity attacks requiring no user interaction. Beyond the zero-day, the update addresses 109 other issues, including 12 remote code execution and 89 privilege escalation vulnerabilities rated critical or high severity.
Pixel devices receive security updates separately from the standard monthly patches distributed to Android OEMs because Google directly controls their unique hardware platform and exclusive features. Users can install the fixes by navigating to Settings, then Security privacy, then System updates, tapping Install, and restarting their devices. The patch follows June's fix for an actively exploited Android Framework zero-day and Google's recent overhaul of its vulnerability rewards program, which offers bounties of up to $1.5 million for certain Android exploits while scaling back payouts for flaws easily found with AI.