There's a serious security fix hiding in Google's September Pixel update
Key Points:
- Google’s September Pixel Drop includes a critical security patch for a cellular modem vulnerability (CVE-2026-58704) that was exploited in limited, targeted attacks on Pixel devices.
- The flaw allows a zero-click attack, meaning no user interaction is needed for the exploit to succeed, posing a significant security risk.
- The US Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities list and mandates federal agencies to apply the patch by September 19, 2026.
- Google’s update also addresses 109 other security issues, including several high-severity flaws, emphasizing the importance for Pixel users to install the latest September 5, 2026, security patch promptly.
- Details on which specific Pixel models were affected or the scope of the exploitation remain unclear.