Google issues urgent update warning for severe Pixel bug
It's not clear which Pixel models are affected.

Image by Cybernews.
- Google says attackers are actively exploiting a Pixel modem flaw that requires no user action.
- The bug could let nearby attackers gain higher access on targeted Pixel devices.
- Google fixed the zero-day in a September update covering 110 Pixel security flaws.
- Pixel owners should install the latest update and check for the September 5th, 2026 patch level or later.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Google is urging Pixel users to update their phones after confirming that attackers are actively exploiting a serious security flaw that requires no user interaction.
The flaw, tracked as CVE-2026-58704, is a security bug in the modem used by some Google Pixel phones.
In its Pixel Update Bulletin, published on Tuesday, Google warns that the high-severity bug could let an attacker take control of a targeted device and does not require the victim to click a link, download an app, or open a malicious file.
Instead, an attacker with access to an adjacent or proximal network could potentially exploit a logic error in the Pixel’s cellular modem.
This could lead to remote proximal/ adjacent escalation of privilege with no additional execution privileges needed,- Google warned in its advisory.
Google has not disclosed who is exploiting the vulnerability or who is being targeted, and has not specified which Pixel models are affected by the actively exploited flaw.
Pixel owners are advised to check for the latest available update and make sure their device shows a security patch level of September 5th, 2026, or later.
Google Patches 110 Pixel security flaws
The zero-day is one of 110 vulnerabilities patched in Google’s September 2026 Pixel security update.
The update also fixes 12 bugs that could let attackers run malicious code remotely and 89 that could give them higher-level access, all rated critical or high severity.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Meanwhile, Lukas Maar, a security researcher at Calif, demonstrated a weakness beyond Google’s control: critically vulnerable manufacturer-added software with deep system access that can let an unprivileged app take full control of Android devices, including the latest flagships from Samsung, Xiaomi, Oppo, and OnePlus.