Credit: Adamya Sharma / Android Authority
TL;DR
- Google’s September Pixel security update patches a cellular modem vulnerability that may have been used in limited, targeted attacks.
- CVE-2026-58704 could allow a remote attacker to bypass permission checks and escalate privileges without requiring any interaction from the victim.
- CISA has added the flaw to its Known Exploited Vulnerabilities list.
Google just released the September Pixel Drop, alongside details of its monthly security fixes for Pixel devices. But amid all the new features that stable Android 17 QPR1 brings, one security flaw may have gone unnoticed. Google and other relevant authorities have now confirmed that a Pixel modem vulnerability, which has now been patched, was used in targeted exploitation.