Google Pixel owners urged to patch actively exploited modem flaw

Imported from official source

Cybersecurity Classified by Officially

Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.”

The bug is not described as a simple remote takeover, but as a vulnerability that could give an attacker who already has a foothold on a phone more power than they should have.

Although Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches distributed to Android manufacturers because of the unique hardware platform Google controls directly and its exclusive features and capabilities.

To apply this month’s security updates, Pixel users should go to Settings > Security & privacy > System & updates > Security update, tap Install, and restart their device to complete the update process.

A supported device with the 2026-09-05 patch level is up to date. After updating, check that the Android security update level shows September 5, 2026, or later.

Technical details

Google says it there are indications that the vulnerability, tracked as CVE-2026-58704, may be under limited, targeted exploitation. Found in the cellular modem, it is a possible permission bypass caused by a logic error in the code. This could lead to remote escalation of privilege (EoP) with no additional execution privileges or user interaction needed.

The vulnerability affects the modem component of Pixel devices and is rated high severity. The modem is the part of a smartphone that handles communication with mobile networks. It allows a phone to connect for calls, texts, and mobile data. Because it is such an important component, a flaw affecting it deserves attention, even if the conditions needed to exploit it limit the number of potential victims.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 20, 2026 19:52
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-act...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.