Google is urging Pixel users to update their smartphones as soon as possible after confirming that attackers are already exploiting a serious security vulnerability. The attack requires no action from the device owner.
The vulnerability, tracked as CVE-2026-58704, is linked to a security flaw in the cellular modem used in some Google Pixel smartphones. In a Pixel security bulletin published on Tuesday, Google warned that the issue is rated high severity and is already being exploited in real-world attacks.
What makes CVE-2026-58704 particularly concerning is that exploitation does not require the victim to click a malicious link, download an app, or open an infected file. An attacker with access to an adjacent or nearby network could potentially exploit the logic flaw in the Pixel modem to escalate privileges on the device.
Google describes the potential impact as follows:
“This could lead to remote proximal/adjacent escalation of privilege with no additional execution privileges needed.”
More information about CVE-2026-58704 is available in the NVD database.
Google has not disclosed who is exploiting the vulnerability or who is being targeted. The company also did not specify which Pixel models are affected by the actively exploited flaw.
Pixel owners are advised to check for the latest available updates and make sure their smartphones are running the September 5, 2026 security patch level or later.
CVE-2026-58704 is just one of 110 vulnerabilities Google addressed in its September security update for Pixel devices. The update also fixes 12 flaws that could have allowed attackers to remotely execute malicious code and 89 vulnerabilities that could have been used to gain elevated privileges within the system.
All of these issues were rated either critical or high severity. Therefore, even Pixel users who have not noticed anything suspicious on their devices should not delay installing the September security update.