19 SEP 2026 — A flaw in the cellular modem inside Google Pixel phones can be exploited without the owner touching anything, and federal agencies in the United States had until today to patch it.
Google says the vulnerability "may be under limited, targeted exploitation." That hedged wording is the strongest claim the company has made.
What the flaw does
CVE-2026-58704 is a permission bypass caused by a logic error in modem code, scored at 8.0. It allows an attacker who is nearby on the network to escalate privileges without needing any execution rights of their own.
The delivery is the part that matters. Reaching the modem requires nothing from the owner, so there is no link to avoid and no attachment to refuse. The Hacker News reported that it can be triggered silently and without any interaction from the device owner.
The fix is in the security patch level dated 5 September 2026 or later, reachable under Settings, then Security and privacy. The same bulletin closes 110 flaws in total, 46 of them rated critical, across components including the bootloader, the IP multimedia subsystem and the trusted execution environment.
Three days from listing to deadline
CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 16 September and set a federal remediation deadline of 19 September. Three days is short even for a catalogue built for urgency.
That interval is the agency's own judgement of how quickly this one matters. It is the clearest signal available about the seriousness of the exploitation, because Google has not described it beyond one hedged sentence.
Why the modem is hard to defend
The cellular modem is a separate computer from the phone's main processor. It runs its own firmware and answers to the mobile network, not the operating system. A flaw there can be reached without the user ever unlocking the screen.
That separation is also why patching is awkward. Modem firmware updates travel through the device vendor rather than the operating system's usual channels, and a device that has stopped receiving vendor updates cannot be fixed by anything the owner does.
For Pixel devices the path is comparatively short, because Google makes both the phone and the update. Across the wider Android estate the same class of flaw takes considerably longer to reach users, because updates must pass from chipset vendor to handset maker to carrier.
What is not known
No actor has been named, no victim has been named, and no date has been given for when exploitation began. The word "targeted" usually indicates a specific list rather than opportunistic scanning, and a zero-click modem bug is expensive enough to build that it is rarely spent widely.
Neither reading is confirmed. Attribution on this class of flaw normally arrives later, from whoever handles the incident response, and the absence of detail this week means nothing either way.
Nor has Google credited a researcher. That is unusual enough to notice. Discovery credit is standard practice in Android bulletins, and its absence here is consistent with a flaw found through incident response rather than through a disclosure programme, though the company has not said so.
What owners should check
Open Settings, then Security and privacy, and confirm the security patch level reads 5 September 2026 or later. That single date covers this flaw and the other 109.
The federal deadline has passed as of today. That tells you what CISA thought of the risk but does nothing for anyone outside those agencies. Consumer devices update on their owners' schedules. A phone that has not been opened this week is still exposed.
The next question is whether this flaw reaches the wider Android estate. The flaw is in modem code, and modem code is rarely unique to one handset maker, so the question is whether other vendors ship the same component and how long their update chains take.