Security · September 21, 2026

Google patches zero‑day in Pixel phones

black floor lamp on living room sofa
Toa Heftiba / Unsplash

Google released September security patches for Pixel smartphones that fix 110 vulnerabilities. Among them is a zero‑day CVE‑2026‑58704 discovered in the cellular modem. The company warned that the flaw is already being used by attackers in targeted operations. The vulnerability received a CVSS score of 8.0 and allows privilege escalation on the device. It stems from a logic error in the cellular modem that enables an attacker to bypass permission checks without any user interaction such as clicking a link or opening a file.

This makes it suitable for zero‑click exploits that can remotely elevate privileges. Google noted signs of limited targeted exploitation but did not disclose who is using the bug or against whom the attacks are directed. On September 16 2026 the US Cybersecurity and Infrastructure Security Agency added CVE‑2026‑58704 to its Known Exploited Vulnerabilities catalog. The September patches also address 109 additional issues including 88 privilege‑escalation bugs ten information‑disclosure flaws nine remote‑code‑execution bugs and two DoS bugs.

Two serious kernel‑privilege‑escalation bugs CVE‑2026‑56914 and CVE‑2026‑58773 were also fixed. Additionally 46 critical problems were resolved in components such as BigOcean Bootloader IP Multimedia Subsystem and Trusted Execution Environment.