Google has discovered a high-severity Android zero-day vulnerability affecting Pixel smartphones, and it has released emergency patches as part of the September 2026 Pixel Update Bulletin. The flaw, tracked as CVE-2026-58704, resides in the device Modem subcomponent and is being exploited in limited, targeted attacks. Google notes the exploit is low on complexity and doesn’t require user interaction, meaning a victim doesn’t need to click a link, install an app, or make any mistakes for the intrusion to succeed.

The “limited, targeted” language Google uses is the same it’s historically applied to zero-days used by commercial spyware vendors and state-aligned surveillance operators, suggesting a narrow but high-value victim set rather than mass exploitation.

Several critical-severity RCE flaws affect components such as the IP Multimedia Subsystem, libpixelimsmedia, the VPU, the Modem, and the BigOcean media engine, while a long list of bootloader, Trusted Execution Environment, and Titan-security-related components received critical EoP fixes. The Pixel patches build on the wider September 2026 Android update, which SecurityWeek reported addressed roughly 180 vulnerabilities across the ecosystem, including dozens of critical flaws, such as the Wi-Fi memory-corruption bug CVE-2026-28662. Given the confirmed exploit, applying this patch should be viewed as urgent rather than routine, particularly for journalists, executives, activists, and other individuals who fall within the typical target range of proximal, zero-click modem exploits.