Google Patches Actively Exploited Zero-Day in September Pixel Security Update
Google has released its September 2026 security patches for Pixel devices, addressing 110 vulnerabilities including one zero-day flaw confirmed to be under active exploitation in targeted attacks.Zero-Day Vulnerability D…

Google has released its September 2026 security patches for Pixel devices, addressing 110 vulnerabilities including one zero-day flaw confirmed to be under active exploitation in targeted attacks.
Zero-Day Vulnerability Details
The company warned that CVE-2026-58704 may be subject to limited, targeted exploitation. All supported Pixel devices will receive the update at the 2026-09-05 patch level.
The high-severity vulnerability stems from improper authorization and protection mechanism failures in the Modem subcomponent. Attackers with access to an adjacent network and basic device privileges could exploit the flaw in low-complexity attacks requiring no user interaction.
“In Cellular Modem, there is a possible permission bypass due to a logic error in the code,” according to the security advisory. “This could lead to remote proximal/adjacent escalation of privilege with no additional execution privileges needed.”
Additional Vulnerabilities Addressed
Beyond the actively exploited zero-day, the September update addresses 109 additional security issues, including 12 remote code execution vulnerabilities and 89 privilege escalation vulnerabilities rated critical or high severity.
Pixel Update Schedule
Google Pixel devices operate on a separate update schedule from standard Android OEM patches due to the unique hardware platform Google controls directly and its exclusive features.
Installation Instructions
To install the updates, Pixel users should navigate to Settings, then Security & privacy, followed by System & updates, tap Security update, select Install, and restart the device to complete the process.
Users can find complete details in Google‘s September 2026 Pixel security bulletin.
Previous Vulnerability and Bug Bounty Program Updates
In June, Google addressed another actively exploited zero-day affecting Android Framework, identified as CVE-2025-48595. That flaw could allow attackers to gain code execution and escalate privileges on devices running Android 14 or later. The company has also overhauled its vulnerability rewards programs, reducing payouts for flaws easier to discover using AI while offering bounties up to $1.5 million for certain Android exploits.


