BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 16, 2026 · 2 min read · Original story

Google fixes actively exploited Android zero-day on Pixel devices

Google fixes actively exploited Android zero-day on Pixel devices

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.

"There are indications that CVE-2026-58704 may be under limited, targeted exploitation," the company warned on Wednesday.

"All supported Google devices will receive an update to the 2026-09-05 patch level. We encourage all customers to accept these updates to their devices."

This high-severity security flaw stems from improper authorization and protection mechanism failure weaknesses affecting the Modem subcomponent. Successful exploitation can allow attackers with access to an adjacent network and basic privileges on the targeted device to escalate privileges in low-complexity attacks that don't require user interaction.

"In Cellular Modem, there is a possible permission bypass due to a logic error in the code," a security advisory issued today says. "This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed."

Google tagged 109 other security issues in this month's Pixel update bulletin, including 12 remote code execution and 89 privilege escalation vulnerabilities rated critical or high severity.

Although Google Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches distributed to Android OEMs because of the unique hardware platform Google controls directly and its exclusive features and capabilities.

To apply this month's security updates, Pixel users must go to Settings > Security & privacy > System & updates > Security update, tap Install, and restart their devices to complete the update process.

You can find more information on the September 2026 updates for Pixel devices in the security bulletin for Google's smartphone range.

In June, Google also addressed an Android Framework zero-day flaw (CVE-2025-48595) that was actively exploited in targeted attacks and could let attackers gain code execution and escalate privileges on devices running Android 14 or later.

One month earlier, the company announced an overhaul of its Android and Chrome vulnerability rewards programs, scaling back payouts for flaws that are easier to find using artificial intelligence (AI) while offering bounties of up to $1.5 million for some Android exploits.

Update September 16, 06:06 EDT: Fixed link to Pixel update bulletin.

References in this story

  1. NVD - Home nvd.nist.gov
  2. Redirecting... source.android.com
  3. CWE - CWE-285: Improper Authorization (4.20) cwe.mitre.org Common Weakness Enumeration (CWE) is a list of software weaknesses.
  4. CWE - CWE-693: Protection Mechanism Failure (4.20) cwe.mitre.org Common Weakness Enumeration (CWE) is a list of software weaknesses.
  5. Google fixes one actively exploited Android zero-day, 124 flaws www.bleepingcomputer.com Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
  6. Google now offers up to $1.5 million for some Android exploits www.bleepingcomputer.com Google overhauls its Android and Chrome vulnerability rewards programs, offering bounties of up to $1.5 million for the most difficult exploits while scaling back payouts for flaws that artificial intelligence (AI) has…

← Back to all news