Google fixes actively exploited Android zero-day on Pixel devices
Google patched 110 Pixel flaws including CVE-2026-58704, a modem privilege-escalation zero-day under limited targeted exploitation.
Google's September 2026 Pixel security update fixes 110 vulnerabilities, including CVE-2026-58704, a high-severity zero-day in the Cellular Modem subcomponent that Google says is under limited, targeted exploitation. The improper-authorization flaw lets attackers with adjacent network access and basic privileges escalate privileges without user interaction. The bulletin also includes 12 remote code execution and 89 privilege escalation flaws rated critical or high severity.