Google patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem that shows signs of limited targeted exploitation. The vulnerability allows remote privilege escalation without user interaction and can be exploited in zero-click attacks. Google also released patches for 109 other security flaws in September 2026, with CISA adding the modem flaw to its Known Exploited Vulnerabilities catalog.