Please, rotate your device

Mobile apps and games

Google has released a security update for Pixel phones that fixes CVE-2026-58704. According to the company, there are indications that the vulnerability was under limited, targeted exploitation.

The issue was found in the phone’s modem, the component responsible for connecting the device to mobile networks. The fix is included in the September 5, 2026 security patch level and later updates.

Owners of supported Pixel models are advised to check for the update and install it as soon as possible.

What is known about CVE-2026-58704

Google disclosed the vulnerability on September 15 in its September Pixel security bulletin.

CVE-2026-58704 has a high severity rating and is classified as a privilege escalation vulnerability. This means an attacker could, under certain conditions, gain broader access to the system than the affected component should normally allow.

In this case, the issue affects the modem. It operates in an isolated environment, but successful exploitation could help an attacker escape those restrictions and reach other parts of the phone.

A detailed technical description and instructions for exploiting CVE-2026-58704 have not been made public. Limiting these details reduces the risk of other attackers quickly reproducing the technique before most users install the update.

The attack could work without any action from the Pixel owner

According to TechCrunch, the vulnerability could be exploited without any interaction from the phone owner. A user would not need to follow a link, open a file or install an unofficial app.

This type of attack is known as zero-click. It is particularly dangerous because the usual precautions taken when handling messages and files may not be enough to protect a device.

However, Google has only reported limited, targeted exploitation of CVE-2026-58704. The company has not disclosed:

  • who was behind the attacks;

  • how many users were affected;

  • where the attacks occurred;

  • which Pixel models were targeted;

  • what information the attackers may have accessed.

There is currently no evidence that the vulnerability was used in a widespread campaign against all Pixel owners.

Why it is called a zero-day vulnerability

CVE-2026-58704 can be described as a zero-day vulnerability because it was reportedly used in real attacks before users had access to a security fix.

Now that an update is available, the issue is no longer unpatched. However, phones that have not received or installed the current security update may remain vulnerable.

It is therefore important not only to receive the update notification but also to complete the installation and restart the device when required.

Which update fixes CVE-2026-58704

Google says that all vulnerabilities listed in the September Pixel bulletin are addressed by the September 5, 2026 security patch level or later.

The company intends to provide this patch level to all supported Pixel phones. However, updates roll out gradually and availability may depend on the phone model and mobile carrier.

Google has not published a separate list of models affected specifically by CVE-2026-58704. All owners of currently supported Pixel phones should therefore check whether an update is available.

The September package also fixes other security problems in Pixel system components, including critical remote code execution, information disclosure and privilege escalation vulnerabilities.

How to update a Google Pixel

To check for an update manually:

  1. Open the Settings app.

  2. Select System.

  3. Open Software update.

  4. Check for an available update.

  5. Download it and follow the onscreen instructions.

  6. Restart the phone if prompted.

After installation, you can check the security patch date:

  1. Open Settings.

  2. Select About phone.

  3. Open the Android version information.

  4. Find Android security update.

To be protected against CVE-2026-58704, the phone should show a security patch level of September 5, 2026 or later.

What to do if the update is not available yet

Pixel updates do not always reach every device at the same time. Google says a complete rollout can take several weeks, depending on the phone and carrier.

If the update is not yet available:

  • check for it again manually;

  • connect the phone to a stable Wi-Fi network;

  • make sure the battery has enough charge;

  • install the update as soon as it appears;

  • do not download unverified firmware from third-party websites.

Resetting the phone to factory settings does not replace the security update. The official Google patch is required to fix the vulnerability itself.

Should Pixel owners be concerned?

There is no information suggesting a widespread attack. Google’s reference to limited, targeted exploitation indicates that the vulnerability was probably used against selected individuals rather than in a large campaign.

Nevertheless, the possibility of exploitation without clicking a link makes CVE-2026-58704 serious enough that users should not postpone the update. The simplest protection is to install the September patch and confirm that the Android security update is dated September 5, 2026 or later.