Google's September 2026 Pixel security update fixes 110 vulnerabilities in Pixel-specific hardware and firmware, including CVE-2026-58704, an elevation-of-privilege zero-day in the cellular modem. Google reported indications of limited, targeted exploitation of the flaw. An attacker must already hold basic privileges on the device and likely control cellular-network conditions or operate a rogue base station; the issue is not described as remotely exploitable over the general internet.
The update addresses 46 critical, 62 high-severity, and one moderate vulnerability, including nine remote-code-execution flaws, 88 additional elevation-of-privilege issues, 10 information-disclosure bugs, and two denial-of-service flaws. Pixel owners should install the update promptly, as Android Security Bulletin patches do not fully cover Pixel-specific components such as modems, bootloaders, GPUs, and fingerprint hardware; custom ROM users may remain exposed to underlying firmware and hardware defects.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The update addressed CVE-2026-58704, a cellular-modem logic-error vulnerability that can enable privilege escalation by bypassing a permission check. Google reported indications of limited targeted exploitation; attacks require existing low-level device access and may involve a compromised cellular network or malicious base station.
Google published details of its September 2026 Pixel security update, remediating 110 vulnerabilities in Pixel-specific hardware and firmware-related components. The fixes included 46 critical, 62 high-severity, and one moderate-severity issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.