Google has confirmed that a security flaw in the modem of its Pixel phones was likely exploited in real-world attacks before a fix went out. The company’s own Pixel Update Bulletin for September 2026 flags CVE-2026-58704, a modem-related bug, as a vulnerability with signs of active abuse against specific targets.
What Google actually said about CVE-2026-58704
Google’s language is deliberately narrow. In the bulletin’s Announcements section, the company states: “There are indications that CVE-2026-58704 may be under limited, targeted exploitation.” That is Google’s own wording. It stops well short of naming who was targeted, how many devices were affected, or who was behind the attacks.
The bulletin classifies CVE-2026-58704 as an elevation-of-privilege issue rated High severity, affecting the modem subcomponent, tracked internally as bug A-484011314. It sits in a longer list of modem, telephony, and firmware fixes for this month. Several of those are rated Critical, but CVE-2026-58704 is the only one Google flags as possibly already exploited.
9to5Google and TechCrunch, reporting on the same bulletin, describe the underlying flaw as a permission bypass caused by a logic error. Both outlets also note that the US Cybersecurity and Infrastructure Security Agency has added it to its Known Exploited Vulnerabilities catalog. Those characterizations come from the outlets’ own reporting, not from Google’s bulletin text, which stays limited to the sentence above.
Which devices are covered, and what to do
Google says the fix ships with the September 2026 security patch level. Its bulletin confirms that every supported Google device will get updated to that patch level, and urges customers to accept the update once it arrives. Google does not publish a device-by-device list for this bulletin. It applies to whichever currently supported Pixel phones receive Android security updates.
To check where your phone stands, open Settings, then System, then System update, or search for “Security update” directly. If your patch level reads 2026-09-05 or later, the fix is already installed. If it doesn’t, install the pending update as soon as it’s available.
This lands the same week Google began rolling out Android 17 QPR1 to eligible Pixel devices, so it’s worth checking both the QPR1 build and the security patch level together.
One detail worth flagging: CVE-2026-58704 does not appear in Google’s separate, broader Android Security Bulletin for September, which covers the wider Android ecosystem. It shows up only in the Pixel-specific bulletin. That suggests this particular flaw is tied to Google’s own hardware rather than the platform generally, at least based on what Google has published so far.
The rest of the bulletin, in brief
- Critical remote-code-execution bugs in the Modem (CVE-2026-56967), IP Multimedia Subsystem (CVE-2026-55318), libpixelimsmedia (CVE-2026-55343), VPU (CVE-2026-56920), Telephone stack (CVE-2026-58683), and BigOcean (CVE-2026-58710).
- Critical elevation-of-privilege bugs spread across the Bootloader, GSA, Trusted Execution Environment, and Goodix Fingerprint TA components, along with several others.
- No exploitation reported for any of those other issues — the “limited, targeted exploitation” language applies specifically to CVE-2026-58704.

Google’s phrasing leaves real gaps. It doesn’t say how many people were affected, whether the attacks are ongoing, or who was behind them. That’s information that would normally accompany disclosure of an actively exploited flaw. Until Google says more, the safest move is simple. Confirm the September patch has landed rather than wait for detail that may not come.
Sources: Google Pixel Update Bulletin—September 2026, 9to5Google, TechCrunch





