READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Google Patches Pixel Modem Zero-Day That Attackers Already Used Against Targeted Devices

Google Patches Pixel Modem Zero-Day That Attackers Already Used Against Targeted Devices
Google's September 2026 Pixel security update fixes CVE-2026-58704, a modem flaw the company confirms was already exploited in limited, targeted attacks before the patch existed. CISA has given federal agencies until September 19 to patch it. No user interaction is needed to get hit, but the attack requires an adjacent network connection, not open internet access.

Google shipped its September 2026 Pixel Update Bulletin this week, and buried in a list of 110 patched vulnerabilities is one Google says was already being used against real people before the fix existed.

The flaw, tracked as CVE-2026-58704, carries a CVSS severity score of 8.0 out of 10. It lives in the Modem subcomponent, the dedicated baseband chip inside every Pixel that handles cellular communication separately from the main Android processor. Google's advisory states plainly: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation."

Google's statement confirms a zero-day was weaponized against specific targets before a patch shipped. The company has not said how many devices were hit, which models were targeted, who did it, or why. According to ExtremeTech and Security Affairs, no attribution to any commercial spyware vendor or state-sponsored group has been established. Tech Times' headline framed the bug as tied to "spyware tradecraft," but the reporting behind that framing doesn't establish who exploited it or confirm a spyware vendor was involved. Google's own advisory makes no such attribution either.

What The Bug Actually Does

According to the description logged in the National Vulnerability Database and cited by The Hacker News, Bleeping Computer, and Security Affairs, the issue is "a possible permission bypass due to a logic error in the code" in the Cellular Modem. It can lead to remote escalation of privilege, and critically, "no additional execution privileges needed" and "user interaction is not needed for exploitation."

This is a zero-click flaw, meaning a target doesn't have to tap a malicious link or open a file. Bleeping Computer specifies the attack vector as requiring "access to an adjacent network and basic privileges on the targeted device," which is a meaningful caveat. Malwarebytes lays out the practical limit clearly: this is not a remote takeover from anywhere on the internet, and Google hasn't said that mere wireless proximity is enough on its own. An attacker likely needs to already have some foothold or be on a nearby network before this bug lets them escalate. Security Affairs makes the same point, describing the attack vector as "adjacent rather than broadly Internet-facing."

Modem-level bugs are prized in targeted operations precisely because they sit below the layer most phone security software monitors, as Tech Times noted in its rundown of the baseband architecture.

The Rest of the Bulletin

CVE-2026-58704 is one bug among 110 fixed this month. The Hacker News breaks the remainder down as 88 privilege escalation flaws, 10 information disclosure issues, nine remote code execution bugs, and two denial-of-service vulnerabilities, including two high-severity kernel privilege escalation flaws (CVE-2026-56914 and CVE-2026-58773) and 46 critical-severity issues across components like BigOcean, Bootloader, IP Multimedia Subsystem, and the Trusted Execution Environment. Bleeping Computer's count of the remaining issues differs slightly, citing 12 remote code execution and 89 privilege escalation bugs rated critical or high. Both outlets agree on the total of 110 and that CVE-2026-58704 is the only one confirmed as actively exploited.

All supported Pixel devices get bumped to the 2026-09-05 patch level. To install it, go to Settings, then Security & privacy, then System & updates, then Security update, per Bleeping Computer and Malwarebytes. Google wants everyone on this immediately, not on their own schedule.

Federal Deadline and the Pixel 11 Question

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog on September 16, 2026, according to The Hacker News. That listing requires Federal Civilian Executive Branch agencies to apply the fix by September 19, 2026, a three-day turnaround that signals how seriously CISA is treating a bug already used against real targets.

One open question flagged by Times Now: Google's newly launched Pixel 11 line switched to a MediaTek modem, a break from the Samsung-built modems in earlier Pixel devices. Google has not said whether the Pixel 11 series is affected by CVE-2026-58704 or whether the confirmed attacks involved that new modem at all. Until Google clarifies which models were actually targeted, Pixel 11 owners are left checking their patch level like everyone else and hoping the September 5 update covers them.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

right
Times NowHackers Could Access Pixel Phones Through This Bug, Google Rolls Out Fix In Latest Update
unknown
The Hacker NewsGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
unknown
MalwarebytesGoogle Pixel owners urged to patch actively exploited modem flaw
unknown
Tech TimesGoogle Patches Actively Exploited Pixel Modem Flaw Linked to Spyware Tradecraft - Tech Times
unknown
Bleeping ComputerGoogle fixes actively exploited Android zero-day on Pixel devices
unknown
Security AffairsGoogle Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
unknown
extremetechGoogle Confirms Targeted Attacks Exploited a Pixel Modem Flaw