Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Google fixes actively exploited Android zero-day on Pixel devices

Google has released its September 2026 security updates for Pixel devices, addressing 110 vulnerabilities, including 1 zero-day flaw that the company says may be under limited, targeted exploitation. BleepingComputer reported the release.

The high-severity flaw, tracked as CVE-2026-58704, affects the Modem subcomponent and involves improper authorization and a protection-mechanism failure. Exploitation requires access to an adjacent network and basic privileges on the targeted device. Google says the flaw can enable a low-complexity privilege-escalation attack without user interaction.

According to Google's advisory, a logic error in the Cellular Modem code can cause a permission bypass, potentially allowing remote, or proximal/adjacent, escalation of privilege without additional execution privileges.

The Pixel bulletin lists 109 other security issues, including 12 remote-code-execution vulnerabilities and 89 privilege-escalation vulnerabilities rated critical or high severity.

All supported Google devices will receive the 2026-09-05 patch level. Pixel devices get separate security updates from the standard monthly patches distributed to Android device manufacturers because Google directly controls their hardware platform and exclusive features. The update is available through Settings > Security & privacy > System & updates > Security update; installation requires a restart.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.