Google has patched the zero-day vulnerability CVE-2026-58704 in the modem of Pixel smartphones. The fix shipped on September 15, 2026, and was included in the security patch dated September 5, 2026. According to Google, the bug was used in a small number of targeted attacks, but the company hasn’t disclosed who was behind them.
What happened
This was a flaw in the modem component that let an attacker escalate privileges and break out of the modem’s sandbox. That means they could potentially access other data on the device.
How the vulnerability worked
The exploit could run completely under the radar—owners didn’t have to click anything or open any files. Basically, the device could be compromised without any action from the user.
What we know about exploitation
Google confirmed some signs of limited—but real—use of the vulnerability in targeted attacks. They haven’t shared details about the attack vectors or the groups involved.
The patch is part of the September 5, 2026 security update and rolled out to Pixels on September 15. Users are protected after installing the update.