Zero-day is being exploited: Google urgently advises Pixel users to update
Google has closed a zero-day security flaw in Pixel smartphones that the company says has already been exploited in some limited and targeted attacks.
Targeted attacks
The vulnerability listed under CVE-2026-58704 is in the cellular modem of the devices and is rated as high in severity. Google therefore recommends that all users who use a Pixel smartphone install the September update immediately. This was made available with the required security patch on September 5th.
According to the description, the vulnerability is based on an error in the authorization check of the modem code. This allows an attacker to increase their rights on the device under certain conditions. No additional execution authorization or interaction from the user is required to successfully exploit the error, it said. The attack can also occur from the immediate vicinity of the affected device.
Google has not yet named a specific attacker or group behind the attacks observed. However, the wording that CVE-2026-58704 is only exploited in a limited and targeted manner suggests that the vulnerability is not part of a widely used malware. Rather, some users are likely to have been specifically targeted, allowing them to gain possession of valuable information.
Update fixes many bugs
The September update for Pixel also closes numerous other security gaps. In the Pixel Bulletin Google lists a large number of vulnerabilities, including several bugs classified as critical. Affected include modems, telephony, bootloaders, trusted execution environments, graphics and multimedia components as well as various Google-specific system components. Several of the critical vulnerabilities could, under certain conditions, enable the execution of malicious code or an escalation of privileges.
The regular Android security update for September also contains numerous fixes. Google describes one of the vulnerabilities closed there as particularly serious because it could allow remote code execution without additional permissions and without required user interaction.
RS News or Research Snipers focuses on technology news with a special focus on mobile technology, tech companies, and the latest trends in the technology industry. RS news has vast experience in covering the latest stories in technology. Can be reached at author2@researchsnipers.com