Google has released its September 2026 security updates for Pixel devices, addressing 110 vulnerabilities, including 1 zero-day flaw that the company says may be under limited, targeted exploitation. BleepingComputer reported the release.
The high-severity flaw, tracked as CVE-2026-58704, affects the Modem subcomponent and involves improper authorization and a protection-mechanism failure. Exploitation requires access to an adjacent network and basic privileges on the targeted device. Google says the flaw can enable a low-complexity privilege-escalation attack without user interaction.
According to Google's advisory, a logic error in the Cellular Modem code can cause a permission bypass, potentially allowing remote, or proximal/adjacent, escalation of privilege without additional execution privileges.
The Pixel bulletin lists 109 other security issues, including 12 remote-code-execution vulnerabilities and 89 privilege-escalation vulnerabilities rated critical or high severity.
All supported Google devices will receive the 2026-09-05 patch level. Pixel devices get separate security updates from the standard monthly patches distributed to Android device manufacturers because Google directly controls their hardware platform and exclusive features. The update is available through Settings > Security & privacy > System & updates > Security update; installation requires a restart.
Comments
0No comments yet. Be the first to comment.