Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has already been exploited in the wild.
“In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the advisory.
The vulnerability is an elevation-of-privilege issue caused by a permission bypass resulting from a logic error in the modem code. Google said there are indications that the flaw may have been used in “limited, targeted exploitation.”
“There are indications that CVE-2026-58704 may be under limited, targeted exploitation.” states Google.
As usual, the IT giant has not disclosed who exploited the vulnerability, how many devices were targeted, or what the attacks were designed to achieve.
The vulnerability is particularly notable because it does not require user interaction. According to the CVE record, exploitation can result in remote, proximal or adjacent privilege escalation without requiring additional execution privileges.
The technical details suggest that an attacker able to reach the vulnerable modem environment could exploit the permission bypass to obtain higher privileges. The attack vector is classified as adjacent rather than broadly Internet-facing, an important distinction when assessing the practical exploitation requirements.
The flaw resides in a critical component of moder architecture. Unlike vulnerabilities affecting applications or higher-level Android components, CVE-2026-58704 resides in the cellular modem, a security-sensitive component responsible for communications between the device and mobile networks.
Modem vulnerabilities have historically attracted attention because they can operate below much of the Android application security model. They can also provide attackers with a path toward privileged access without relying on conventional malicious applications or phishing.
In this case, however, Google has not publicly described the complete attack chain. There is also no evidence in the company’s advisory identifying the operation as the work of a commercial spyware vendor or a specific state-sponsored group.
The limited-targeted nature of the exploitation is nevertheless notable.
It suggests that exploitation was not necessarily widespread and may have been directed at a small number of selected devices. Without additional information from Google or independent researchers, the targets and objectives remain unknown.
CVE-2026-58704 is only one of many vulnerabilities addressed by Google’s September Pixel release.
Google’s official Pixel bulletin lists additional security issues affecting components including the kernel, modem, bootloader, telephony stack, Trusted Execution Environment, GPU, Bluetooth, NFC, pKVM and several proprietary Pixel components. The bulletin includes multiple critical-severity vulnerabilities, including remote-code-execution flaws affecting the IP Multimedia Subsystem, libpixelimsmedia, VPU, modem, telephone and BigOcean components.
The broader September Android security bulletin also addresses additional vulnerabilities across the Android platform. Google states that devices using the 2026-09-05 security patch level or later are protected against the issues covered by the Pixel bulletin and the September Android Security Bulletin.
Google’s wording is deliberately limited: it says there are indications that CVE-2026-58704 may be under limited, targeted exploitation.
That is different from saying that the vulnerability is being widely exploited.
At the same time, the confirmation that exploitation has occurred changes the risk profile for affected Pixel users. A vulnerability that exists only as a theoretical security issue can be evaluated differently from one for which exploitation has already been observed.
The absence of public attribution also leaves several questions unanswered.
Was the vulnerability discovered and exploited by a private surveillance company? Was it used by a state-linked operation? Was it part of a broader intrusion chain targeting specific individuals?
At this stage, there is insufficient public evidence to answer those questions.
In the past, exploits of this kind have been used by nation-state actors and commercial spyware vendors.
What is clear is that Google considered the issue serious enough to disclose exploitation and include the fix in its September Pixel security release.
Google recommends that supported Pixel devices receive the latest security update. The 2026-09-05 security patch level addresses the vulnerabilities listed in the September Pixel bulletin as well as those covered by the Android security bulletin.
For users and organizations managing Pixel fleets, the exploitation status of CVE-2026-58704 makes timely patching particularly important.
The incident also highlights a broader security reality: the attack surface of a smartphone extends far beyond the applications installed by the user.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Pixel Modem)