The immediate action is straightforward: confirm enrolled Pixel devices have installed the September 15 release and report a security patch level of 2026-09-05 or later. Google’s Pixel Update Bulletin says that level covers both its Pixel-specific fixes and the September Android Security Bulletin. The update is rolling out alongside Android 17 QPR1, and 9to5Google reports that the current global OTA build is CP3A.260905.009 for supported devices.
BleepingComputer first reported the update as a package of 110 Pixel-specific vulnerabilities, including the exploited modem issue. Google’s own bulletin substantiates that total: it lists 110 issues beyond the vulnerabilities covered in the separate Android Security Bulletin. This is an important distinction for administrators tracking monthly patch exposure. “September Android security patch installed” is not sufficient evidence by itself that a Pixel has received every Google-device fix; the phone needs the 2026-09-05 patch level.
CVE-2026-58704 is an adjacent-network modem attack path
Google classifies CVE-2026-58704 as an elevation-of-privilege flaw in the Modem subcomponent and assigns it High severity. Its technical description is notably short: a logic error can enable a permission bypass in the cellular modem, leading to remote, proximal privilege escalation without further execution privileges.
In practical terms, adjacent means an attacker must be in range of the target’s cellular communications rather than merely sending a phishing email from anywhere on the internet. That substantially narrows the likely operating conditions compared with a browser or messaging zero-click flaw. It does not, however, make the bug a routine local-app escalation: the modem is a separate, radio-facing component, and the stated lack of user interaction removes the most common warning sign that prompts users to stop an attack.
Google has not named the affected Pixel models, the chipset or modem supplier involved, the attackers behind the activity, victims, geographic scope, exploit chain, or indicators defenders could use to identify an attempted compromise. The bulletin marks the linked Android bug record as non-public, so outside researchers cannot yet inspect the patch or independently reproduce the condition. The company’s wording also matters: it reports “indications” of “limited, targeted exploitation,” rather than confirming broad in-the-wild attacks.
That leaves a firm operational conclusion but a limited threat-intelligence one. Pixel fleets should patch promptly because Google has acknowledged active targeting; security teams should not infer from the advisory that ordinary users are facing a mass, remotely exploitable modem worm.
The “110 vulnerabilities” are Pixel additions, not September’s entire Android tally
The largest reporting trap in this update is the number. Google’s Pixel bulletin contains 110 vulnerabilities, but it expressly says these are in addition to the September 2026 Android Security Bulletin. The Android bulletin itself contains vulnerabilities addressed at the 2026-09-01 and 2026-09-05 patch levels, including critical System issues that Google says could allow remote code execution without user interaction.
9to5Google counted 115 Android security issues associated with the September patch material and 110 additional fixes in the dedicated Google-device bulletin. The figures should not be casually added and presented as an exact count of independently exploitable flaws on every Pixel: the two bulletins cover different layers and include device-, component-, and version-dependent fixes. What administrators can say with confidence is that a fully updated Pixel receives the Android bulletin’s fixes plus a large set of Pixel-specific fixes.
The Pixel-only table spans more than the modem. It includes critical and high-severity entries for bootloader components, the Trusted Execution Environment, KeyMint, Android Verified Boot, NFC, Bluetooth, the Google app component identified as GSA, telephony, fingerprint trusted applications, GPUs, Tensor-related components, pKVM, and several media or connectivity elements. Twelve of the Pixel bulletin’s entries are remote-code-execution vulnerabilities, while the dominant category is elevation of privilege.
That distribution is relevant to managed-device risk. Most privilege-escalation bugs become more dangerous after an attacker already has some foothold—through a malicious app, physical access, a separate exploit, or abuse of an existing account or service. Modem flaws deserve special attention precisely because they can provide a different route into that chain.
A security patch level is the simplest verification control
Google says every supported Pixel will receive an update to the 2026-09-05 patch level. The cleanest audit check is therefore not whether users saw an Android 17 QPR1 prompt or whether they are on a particular marketing version of Android, but the device’s recorded security-patch date.
On a Pixel, open Settings > Security & privacy > System & updates > Security update and install the available package. After the restart, verify the Android security update line shows September 5, 2026 or a later date. IT teams using Android Enterprise management should inventory that security patch date through their EMM or unified-endpoint-management platform and create a compliance rule for anything below 2026-09-05.
A practical response for organizations with company-owned or BYOD Pixels is to:
- Require the September 2026 update on supported Pixel devices before allowing continued access to email, VPN, device certificates, and other sensitive corporate services.
- Identify devices that remain on the September 1, 2026 patch level, because that date does not establish that the Pixel-specific modem fix is present.
- Follow up with users whose devices have pending restarts, since downloading the update without completing installation leaves the old vulnerable firmware active.
- Escalate exceptions involving executives, journalists, developers with production access, administrators, or other personnel whose work could make them plausible targets for limited and targeted surveillance activity.
The patch is available as an over-the-air update, and Google also publishes full OTA packages. The latter can be useful when an OTA installation has failed, but it is an exception path rather than the right default for a broad enterprise rollout. An organization should avoid treating sideloading as its standard remediation process unless it has the device-management controls, image-validation process, and recovery procedures to support it.
Pixel’s timely patch does not solve Android fleet exposure
Google’s direct update control gives Pixel users an advantage in this incident: its own bulletin promises supported Google devices the 2026-09-05 patch level, and the company can pair device-specific firmware work with Android’s monthly patches. Other Android manufacturers must adapt and distribute patches across their own hardware combinations, carriers, regional SKUs, and modem firmware arrangements.
But CVE-2026-58704 should not be generalized into a claim that every Android handset is vulnerable. Google has documented it in the Pixel Update Bulletin under its Modem subcomponent, not in the general Android Security Bulletin. The public record currently supports an urgent Pixel patch recommendation; it does not establish which non-Pixel phones, if any, share the underlying exposure.
For mixed mobile fleets, that means separating two questions that are often collapsed into one: whether a device has the September Android security fixes, and whether its vendor has shipped all applicable proprietary firmware updates. A Samsung, Motorola, or carrier-issued phone on a current-looking Android version may have a different patch state from a Pixel, even where the visible monthly security date appears similar.
Google says it notifies Android partners of bulletin issues at least a month before publication. That process helps vendors prepare, but it does not guarantee that an update has reached every endpoint by the day Google publishes its Pixel package. Administrators should use their vendor’s documented patch bulletin and device inventory data rather than assume the Pixel release equals universal Android coverage.
The urgent part is precise, even if Google’s details are sparse
The September release also includes functional fixes across supported Pixels, according to 9to5Google, including repairs for mobile-network connection failures or unexpected service interruptions, gaming performance and heat problems, app crashes, Wi-Fi and Bluetooth enablement failures on certain Pixel 10-series devices, and notification and display glitches. Those improvements may encourage users to install the update, but they should not distract from the security requirement.
The security case rests on a narrower fact: Google has acknowledged targeted exploitation of a modem permission-bypass vulnerability and says the 2026-09-05 patch level addresses it. Until Google publishes attack details or a public patch analysis, defenders should avoid inventing an attribution story around the flaw.
For now, the measurable outcome is simple. A Pixel that reports a security patch level earlier than September 5, 2026 has not met Google’s stated remediation level for CVE-2026-58704 and the rest of this month’s Pixel-specific fixes.
Update: Pixel 11 remains below Google’s stated remediation level (September 16, 2026)
Notebookcheck reports that Google’s September 15 Pixel release covers the Pixel 6 through Pixel 10 families, but not the newer Pixel 11 series. Pixel 11 devices have reportedly received two September updates—on September 1 and September 10—yet still show a 2026-09-01 security patch level.
That matters because Google identifies 2026-09-05 as the level needed for the September Pixel bulletin’s full set of fixes, including CVE-2026-58704. Google has not said whether the modem vulnerability affects Pixel 11 hardware, nor has it announced when Pixel 11 will receive an update carrying the September 5 patch level.
Administrators should therefore avoid marking Pixel 11 devices compliant solely because they received a September update. Until Google publishes clarification or a newer patch, inventory should distinguish Pixel 11 units at 2026-09-01 from Pixel 6–Pixel 10 devices that have reached 2026-09-05 or later.