Google has confirmed that a “limited” number of Pixel phones were attacked by a vulnerability related to the modem on the device.

As part of the September 2026 security update, Google patched over 200 security vulnerabilities, but specifically calls out that one of those was actively exploited in the wild.

Note: There are indications that CVE-2026-58704 may be under limited, targeted exploitation.

The issue is related to the modem, with a bypass that requires no user interaction. CVE-2026-58704 is described as follows:

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Exact details of how the vulnerability was exploited are unclear – as well as which models were affected – but CISA (via The Hacker News) says that it was exploited on Pixel phones, explaining that “Google Pixel devices contain an improper authorization vulnerability in the cellular modem.” Combined with Google’s announcement, this was used in the wild, apparently to hack “targeted” devices. CISA issued a notice that this is a “known exploited vulnerability,” explaining that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” TechCrunch notes that this is called a “zero-click” attack, adding that Google hadn’t replied to a request for comment around the vulnerability being exploited and who was exploiting it.

If you’re on a Pixel phone, updating to the September 2026 patch, rolling out now, fixes the issue.

More on Google Pixel:

- September 2026 Pixel Drop: VIPs widget redesign, more Pixel Watch gestures

- Pixel 11 lets you make any Camera Look default with this buried setting

- Google Pixel adding ‘Battery usage summaries,’ rolling out on Pixel 10 and newer

Follow Ben: Twitter/X, Threads, Bluesky, and Instagram