Pixel modem flaw exploited in limited targeted attacks

Published

Google's September update for Pixel phones carries a line that most monthly patch notes do not. Of the 110 flaws it fixes, one may already be in use against real targets. The bug is CVE-2026-58704, it sits in the phone's cellular modem, and Google's own bulletin says there are indications it "may be under limited, targeted exploitation".

CISA added it to the Known Exploited Vulnerabilities catalog the same day, 16 September, and gave federal civilian agencies until 19 September to act on it.

Google published the flaw and little else

The bulletin entry is four columns wide: the CVE, an internal bug id of A-484011314, a type of elevation of privilege, and a severity of High, filed under the Modem component. CISA's catalog entry adds a single sentence, saying Pixel devices contain an improper authorization flaw in the cellular modem and that a logic error may allow an attacker to bypass permission checks and escalate privileges.

That is the entire public record. Neither Google nor CISA has said who is being targeted, how an attack begins, or what an attacker needs on the phone beforehand, and there is no honest way to fill those gaps in. What can be said is why the component matters: the modem is the subsystem that handles calls, texts and mobile data, and it runs with privileges of its own, which is why a permission flaw there earns attention even when the exploitation is described as limited.

Patch, then check whether you were already hit

The fix ships in the 2026-09-05 security patch level. On a supported Pixel, install the update, restart, and confirm the Android security update level reads 5 September 2026 or later. Pixel phones get their own bulletin separate from the monthly Android release because parts of the hardware, the affected modem among them, are not shared with other Android makers. On a different brand, this particular fix will not reach you, though your manufacturer's September update still should.

The CISA listing carries one detail worth more than the deadline. Under Binding Operational Directive 26-04, the entry is flagged for forensic triage, which means agencies are expected to establish whether a device was compromised before the patch landed rather than treat installation as the end of the matter. That is a sensible standard for anyone carrying a phone that would interest a targeted-intrusion operator, federal or not, and it is the part of a KEV entry that most readers skip.

A steady drumbeat of same-day additions

Nothing about the timing here is unusual any more. CISA now routinely lists a flaw within hours of the vendor disclosing exploitation, and the three-day clock has become the norm rather than an emergency measure. Two days earlier the agency did the same to a Cisco email gateway bug under active attack. What is less common is seeing a consumer handset on the list at all, which is a reminder that the phone in a target's pocket is part of the attack surface an organization owns.

Google's September 2026 Pixel Update Bulletin lists the fix and the exploitation note, and CISA's alert records the catalog addition. For the other half of the mobile threat picture, the part that needs no vulnerability at all, see our coverage of an Android trojan that clones your banking app.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions