Google released its September 2026 Pixel security update to fix CVE-2026-58704, an actively exploited zero-day in the cellular modem component. Google said exploitation is limited and targeted; the improper-authorization flaw can allow a nearby attacker with basic device privileges to bypass access controls and elevate privileges without user interaction.
The update addresses 110 Pixel vulnerabilities overall, including dozens rated critical or high severity. Organizations and users should deploy the 2026-09-05 Android security patch level or later across supported Pixel devices, prioritizing people and fleets at heightened risk of targeted surveillance.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Google published its September 2026 Pixel Update Bulletin, fixing CVE-2026-58704, a Cellular Modem elevation-of-privilege flaw reported to be under limited, targeted exploitation. The update provides the 2026-09-01 and 2026-09-05 Pixel patch levels; devices patched at 2026-09-05 or later are protected from the issue.
Google fixed CVE-2025-48595, an Android Framework zero-day that had been actively exploited in targeted attacks and could enable code execution and privilege escalation on Android 14 or later devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceacn.gov.it
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.