Google Pixel CVE-2026-58704: Install the September 2026 Security Update


Google's September 2026 Pixel Update Bulletin fixes CVE-2026-58704, a high-severity elevation-of-privilege vulnerability in the Pixel modem. Google says there are indications that the flaw may be under limited, targeted exploitation. The bulletin was published on September 15, 2026.

Supported Pixel devices should install the September update and verify a 2026-09-05 or later security patch level. Google says that patch level addresses every issue listed in the September Pixel bulletin as well as the vulnerabilities covered by the September Android Security Bulletin.

CVE-2026-58704 at a glance

Item Detail
CVE CVE-2026-58704
Product scope Supported Google Pixel devices covered by the September Pixel bulletin
Component Modem
Vulnerability type Elevation of privilege (EoP)
Google severity High
Exploitation status Google says there are indications of limited, targeted exploitation
Required Pixel patch level 2026-09-05 or later
Pixel bulletin date September 15, 2026

Google's public bulletin links CVE-2026-58704 to Android bug A-484011314. The asterisk attached to that reference indicates that the underlying issue is not publicly available; Google says fixes for such issues are generally contained in the latest binary drivers for Pixel devices.

What Pixel owners should do

Install the latest system update offered to the device, then check the Android security update field in system settings. The target is 2026-09-05 or later.

Google says all supported Pixel devices will receive the 2026-09-05 patch level. Pixel updates begin rolling out when the monthly bulletin is released, while availability can take roughly a week and a half to reach every supported Google device. Firmware images are also available through Google's developer resources.

For managed fleets, the security patch level provides a straightforward compliance check: devices below 2026-09-05 have not incorporated the complete September Pixel security set described in this bulletin.

Why the Pixel bulletin is separate from the Android bulletin

The September Pixel bulletin supplements the broader Android Security Bulletin with vulnerabilities and fixes specific to Google devices. CVE-2026-58704 appears in the Pixel-specific list, where Google classifies it as a high-severity modem elevation-of-privilege issue.

The broader September Android Security Bulletin was published September 8 and updated September 10. It covers Android platform vulnerabilities and also uses 2026-09-05 as its complete monthly patch level. Google states that the Pixel 2026-09-05 update includes both sets of fixes.

This distinction matters when checking remediation: the Pixel bulletin, rather than the generic Android bulletin alone, is the primary source for CVE-2026-58704 and Google's targeted-exploitation warning.

September's Pixel security update is much larger than one CVE

CVE-2026-58704 is the issue Google singled out for possible targeted exploitation, but the September Pixel bulletin contains a broad device-specific security set. It includes multiple critical remote-code-execution and elevation-of-privilege vulnerabilities across components such as the modem, telephony stack, bootloader, trusted execution environment and Pixel-specific subsystems.

That makes the complete monthly update the appropriate remediation target. Selectively tracking only CVE-2026-58704 would miss other critical fixes delivered in the same Pixel patch level.

Material evidence boundary

Google's bulletin establishes the vulnerability class, severity, modem component, patch level and indication of limited targeted exploitation. The public bug record is restricted, so the bulletin does not provide exploit-chain details or a public technical root-cause analysis. The remediation decision remains clear from Google's published guidance: supported Pixel devices should move to the 2026-09-05 or later security patch level.

Sources

  • Google Android Open Source Project, Pixel Update Bulletin—September 2026, published September 15, 2026.
  • Google Android Open Source Project, Pixel Update Bulletins, for rollout and patch-level guidance.
  • Google Android Open Source Project, Android Security Bulletin—September 2026, published September 8 and updated September 10, 2026.