Google Pixel September 2026 Update Fixes 110 Security Vulnerabilities, Including an Actively Exploited Zero-Day
Google has released its September 2026 security update for Pixel devices, addressing 110 security vulnerabilities, including a zero-day flaw that has been exploited in limited and targeted attacks.
Pixel security update fixes actively exploited modem flaw
Google identified CVE-2026-58704 as a high-severity vulnerability affecting modem subcomponents. The company said there may be limited and targeted exploitation of the flaw in the wild.
According to Google’s Pixel security bulletin, the vulnerability is caused by weaknesses involving improper authorization and protection mechanism failures.
An attacker with access to an adjacent network and basic privileges on the targeted device could exploit the flaw through a low-complexity attack. The attack does not require user interaction and could allow the attacker to escalate privileges remotely.
Cellular modems may allow privilege bypass due to logic errors in the code.
Google’s security advisory states that this could lead to remote, or proximity-based, privilege escalation without requiring additional execution privileges.
109 additional vulnerabilities addressed
Google also addressed 109 other security issues in its September 2026 Pixel update. These include 12 remote code execution vulnerabilities and 89 privilege escalation vulnerabilities rated as critical or high severity.
Pixel devices run Android, but their unique hardware platforms and Google-managed features receive security updates and bug fixes through a separate Pixel update process. This is separate from the standard monthly security patches distributed to other Android device manufacturers.
How to install the September 2026 Pixel update
To check for and install the update, open Settings and go to Security & privacy > System & updates > Security update. Tap Install when the update is available, then restart the device to complete the installation.
All supported Google devices will receive updates to the 2026-09-05 patch level. Google encourages customers to accept and install the updates on their devices.
For more information about the September 2026 Pixel security update, see Google’s official Pixel security bulletin.
Google continues to address Android zero-day vulnerabilities
In June, Google also addressed an Android Framework zero-day vulnerability, CVE-2025-48595. The flaw was actively exploited in targeted attacks and could allow attackers to execute code and escalate privileges on devices running Android 14 and later.
Last month, Google announced an overhaul of its Android and Chrome vulnerability bounty programs. The changes use artificial intelligence to reduce payouts for easy-to-discover flaws while offering bounties of up to $1.5 million for some Android exploits.
Updated September 16, 2026, at 06:06 EDT: Corrected the link to the Pixel update bulletin.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com


