Google Fixes Actively Exploited Pixel Modem Flaw, Patches 109 Other Bugs
Google has disclosed that a high-severity flaw in its Pixel Cellular Modem, tracked as CVE-2026-58704 (CVSS score 8.0), has shown signs of being exploited in the wild. The bug is a permission bypass caused by a logic error, allowing an attacker in close physical or network proximity to escalate privileges without needing extra execution rights or any action from the user. Google has not shared details about who is behind the attacks or how they are being carried out.
The modem flaw was addressed as part of Google's September 2026 Pixel security update, which also fixes 109 other vulnerabilities. Of these, 88 relate to privilege escalation, ten to information disclosure, nine to remote code execution, and two to denial-of-service issues. Notable fixes include two high-severity kernel privilege escalation bugs and 46 critical-severity flaws across components such as the Bootloader, IP Multimedia Subsystem, and Trusted Execution Environment, some of which could allow full remote code execution.
Google says devices with a security patch level of 2026-09-05 or later are protected against all the newly disclosed issues. This is the second actively exploited Android flaw Google has patched in recent months, following a similar high-severity Framework bug fixed in June 2026.