AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Google Confirms a Pixel Modem Flaw Was Used in Targeted Attacks

Androidpure Staff by Androidpure Staff
September 17, 2026
in News

Google has confirmed that a security flaw in the modem of its Pixel phones was likely exploited in real-world attacks before a fix went out. The company’s own Pixel Update Bulletin for September 2026 flags CVE-2026-58704, a modem-related bug, as a vulnerability with signs of active abuse against specific targets.

What Google actually said about CVE-2026-58704

Google’s language is deliberately narrow. In the bulletin’s Announcements section, the company states: “There are indications that CVE-2026-58704 may be under limited, targeted exploitation.” That is Google’s own wording. It stops well short of naming who was targeted, how many devices were affected, or who was behind the attacks.

The bulletin classifies CVE-2026-58704 as an elevation-of-privilege issue rated High severity, affecting the modem subcomponent, tracked internally as bug A-484011314. It sits in a longer list of modem, telephony, and firmware fixes for this month. Several of those are rated Critical, but CVE-2026-58704 is the only one Google flags as possibly already exploited.

9to5Google and TechCrunch, reporting on the same bulletin, describe the underlying flaw as a permission bypass caused by a logic error. Both outlets also note that the US Cybersecurity and Infrastructure Security Agency has added it to its Known Exploited Vulnerabilities catalog. Those characterizations come from the outlets’ own reporting, not from Google’s bulletin text, which stays limited to the sentence above.

Which devices are covered, and what to do

Google says the fix ships with the September 2026 security patch level. Its bulletin confirms that every supported Google device will get updated to that patch level, and urges customers to accept the update once it arrives. Google does not publish a device-by-device list for this bulletin. It applies to whichever currently supported Pixel phones receive Android security updates.

To check where your phone stands, open Settings, then System, then System update, or search for “Security update” directly. If your patch level reads 2026-09-05 or later, the fix is already installed. If it doesn’t, install the pending update as soon as it’s available.

This lands the same week Google began rolling out Android 17 QPR1 to eligible Pixel devices, so it’s worth checking both the QPR1 build and the security patch level together.

One detail worth flagging: CVE-2026-58704 does not appear in Google’s separate, broader Android Security Bulletin for September, which covers the wider Android ecosystem. It shows up only in the Pixel-specific bulletin. That suggests this particular flaw is tied to Google’s own hardware rather than the platform generally, at least based on what Google has published so far.

The rest of the bulletin, in brief

  • Critical remote-code-execution bugs in the Modem (CVE-2026-56967), IP Multimedia Subsystem (CVE-2026-55318), libpixelimsmedia (CVE-2026-55343), VPU (CVE-2026-56920), Telephone stack (CVE-2026-58683), and BigOcean (CVE-2026-58710).
  • Critical elevation-of-privilege bugs spread across the Bootloader, GSA, Trusted Execution Environment, and Goodix Fingerprint TA components, along with several others.
  • No exploitation reported for any of those other issues — the “limited, targeted exploitation” language applies specifically to CVE-2026-58704.
Person holding a blue Google Pixel phone to their ear during a phone call, outdoors
Image: Google

Google’s phrasing leaves real gaps. It doesn’t say how many people were affected, whether the attacks are ongoing, or who was behind them. That’s information that would normally accompany disclosure of an actively exploited flaw. Until Google says more, the safest move is simple. Confirm the September patch has landed rather than wait for detail that may not come.

Sources: Google Pixel Update Bulletin—September 2026, 9to5Google, TechCrunch

Tags: android securitycve-2026-58704Google Pixelpixel update bulletin
TweetShareSendShare
Previous Post

Alexa+ Launches in India With Hindi Support: Price and Features

Androidpure Staff

Androidpure Staff

Androidpure Staff delivers the latest from the Android world — phone launches, software updates, and practical how-to guides — without the press-release fluff. We focus on what genuinely matters to readers, in India and around the globe.

Follow Us

  • 914 Followers

Popular

  • Google G logo, the company's official brand mark

    Pixel 6 and 6 Pro: Google’s 5-Year Update Window Closes in October

    Share
    Share Tweet
  • iOS 27 Releases Monday, September 14: Apple’s Own Timing Confirmed

    Share
    Share Tweet
  • iPhone 18 Pro Max: Some Ship Dates Slip to October Hours Into Pre-Orders

    Share
    Share Tweet
  • Where Is the September Pixel Update? Android 17 QPR1 Still Pending

    Share
    Share Tweet
  • iPhone 18 Pro Pre-Orders Open Today: Trade-In Credit, Carrier Deals, and Ship Dates

    Share
    Share Tweet
  • iPhone 18 Pro Max: US Model Missing Apple’s C2 Modem on Spec Sheet

    Share
    Share Tweet
  • Google Will Pay £260m to Settle UK App Developers’ Play Store Claim

    Share
    Share Tweet

Latest

Person holding a blue Google Pixel phone to their ear during a phone call, outdoors

Google Confirms a Pixel Modem Flaw Was Used in Targeted Attacks

September 17, 2026
Woman using Alexa+ on an Echo Show smart display in an Indian kitchen, showing recommended recipes and smart home controls

Alexa+ Launches in India With Hindi Support: Price and Features

September 16, 2026
Apple's redesigned Screen Time interface on iPhone showing Screen Time Schedule, a child's daily usage chart, and Time Allowances by app category

Apple’s New Child Safety Tools Are Live in iOS 27

September 16, 2026
Apple Security Research padlock and Apple logo graphic representing Apple Reference Image cryptographic photo verification

Apple Reference Image: How iPhone 18 Pro Proves a Photo Is Real

September 16, 2026
One UI 9 Now Nudge feature showing a text conversation with a suggested calendar event on a Samsung Galaxy phone

Samsung Starts One UI 9 Rollout: Galaxy S26 Gets It First

September 16, 2026
Realme 16 Pro Harry Potter Edition rear panel with Hogwarts crest design

Realme 16 Pro Harry Potter Edition Launches in India September 21

September 16, 2026
Apple AirPods 5 and charging case official product photo

AirPods 5 Go on Sale Friday: $129 Price Brings ANC to Apple’s Cheapest Buds

September 16, 2026
AndroidPure

© 2026 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2026 AndroidPure - NonStop Android.