{"id":26125,"date":"2026-10-02T16:48:53","date_gmt":"2026-10-02T12:48:53","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/?p=26125"},"modified":"2026-10-02T16:48:53","modified_gmt":"2026-10-02T12:48:53","slug":"google-pixel-september-2026-security-update","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/google-pixel-september-2026-security-update\/26125\/","title":{"rendered":"Google patches 110 vulnerabilities in Pixel smartphones"},"content":{"rendered":"<p>On September 15 this year, Google published details of patches for 110 vulnerabilities in its own Google Pixel smartphones. Among all the disclosed flaws, <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-58704\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2026-58704<\/a> stands out the most, for it appears that this zero-day is being exploited in targeted attacks.<\/p>\n<p>In today\u2019s post, we talk about what\u2019s so special about the Google Pixel, and why these devices get security updates all of their own \u2013 separate from regular Android updates. We also cover the vulnerabilities addressed in this latest update, with a special focus on the mentioned, most dangerous one \u2013 CVE-2026-58704 \u2013 and wrap up with tips on how to both protect your device and avoid becoming a victim of cyberattack on it.<\/p>\n<h2>Why do Google Pixel phones get security updates separate from Android?<\/h2>\n<p>The reader might reasonably wonder: I\u2019ve already installed this month\u2019s Android security updates on my Google Pixel. Isn\u2019t that the same thing? Google Pixel does run on Android and receives those security updates, which are detailed in the monthly <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/asb-overview\" target=\"_blank\" rel=\"noopener nofollow\">Android Security Bulletin<\/a>. However, manufacturers of Android-based devices use different sets of hardware and software components. That\u2019s why, alongside vulnerabilities common to all Android devices, there are security issues specific to individual manufacturers\u2019 devices.<\/p>\n<p>For its own smartphones, Google publishes separate security updates, covered by a dedicated <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/pixel\" target=\"_blank\" rel=\"noopener nofollow\">Pixel Update Bulletin<\/a>. Rather than replacing the Android Security Bulletin, this document complements it by detailing vulnerabilities specific to devices manufactured by Google. Other Android smartphones also receive similar updates from their manufacturers.<\/p>\n<p>The <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/pixel\/2026\/2026-09-01\" target=\"_blank\" rel=\"noopener nofollow\">Pixel Update Bulletin for September 2026<\/a> clearly shows why Google needs separate updates for its smartphones in the first place. Many of the vulnerabilities it fixes affect specific Pixel hardware (or hardware-related) components: the modem, bootloader, GPU, fingerprint scanner components, and other parts of the device. On smartphones from other manufacturers, these features might rely on entirely different hardware and software components, so the fixes listed in the Pixel Update Bulletin don\u2019t apply to those phones.<\/p>\n<p>That said, these vulnerabilities could still be relevant for Pixel owners who\u2019ve flashed their devices with custom ROMs. Switching to a different OS doesn\u2019t alter the device\u2019s hardware components, and may not replace the firmware. Therefore, the vulnerabilities themselves may persist, but whether patches are available, and how they\u2019re installed, depends on the specific OS.<\/p>\n<h2>CVE-2026-58704: a zero-day vulnerability being actively exploited in the wild<\/h2>\n<p>Now let\u2019s look closer at the specific vulnerabilities Google fixed in September. The most significant one is the above-mentioned <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-58704\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2026-58704<\/a>.<\/p>\n<p>This vulnerability affects the Cellular Modem component, which handles the smartphone\u2019s communication with cellular networks. It stems from a logic error in the code, which, under certain conditions, allows bypassing the intended permission check.<\/p>\n<p>Successful exploitation of CVE-2026-58704 lets attackers escalate privileges on the smartphone to gain broader access to its functions and data. Note that the attack takes place over a cellular network and the threat actors need low-level privileges on the targeted device to start with.<\/p>\n<p>In practice, this means attackers can\u2019t exploit CVE-2026-58704 to attack a Pixel from just anywhere over the internet, as they\u2019d apparently need to either compromise the cellular network the target smartphone is already connected to or, more likely, force it to connect to a malicious base station under their control.<\/p>\n<p>Google hasn\u2019t disclosed all the details of this vulnerability yet, and the related report is not publicly accessible. As a result, the technical details that would show how easy it is for attackers to exploit CVE-2026-58704 remain unknown pending installation of the patches on all devices.<\/p>\n<p>Nevertheless, Google claims that there are signs of limited exploitation of CVE-2026-58704.<\/p>\n<h2>What we know about the other 109 vulnerabilities<\/h2>\n<p>Of the remaining 109 vulnerabilities found in Google Pixel devices, only one is rated moderate; the others are either high (62) or outright critical (46). Nine of these flaws fall into the RCE (remote code execution) category. This means that if an attacker successfully exploits one of these vulnerabilities, they can remotely force the device to run malicious code. The exact conditions for the attack depend on the specific vulnerability.<\/p>\n<p>Another 88 vulnerabilities fall into the elevation of privilege (EoP) category. These let an attacker who\u2019s already gained a certain level of access to the device expand their privileges. The CVE-2026-58704 vulnerability discussed above falls into this same category, which is why the September bulletin lists 89 EoP vulnerabilities in total.<\/p>\n<p>Finally, 10 vulnerabilities can lead to information disclosure (ID), and two more to denial of service (DoS). In short, that\u2019s a hefty list of flaws, so Google Pixel owners shouldn\u2019t wait around to install the patches.<\/p>\n<h2>How to avoid becoming a victim<\/h2>\n<p>Google Pixel owners can install the update that fixes the vulnerabilities covered in this post by following this path: <em>Settings<\/em> \u2192 <em>Security &amp; privacy<\/em> \u2192 <em>System &amp; updates<\/em> \u2192 <em>Security update<\/em> \u2192 <em>Install<\/em>. Keep in mind that the phone will automatically restart to finish installing the update.<\/p>\n<p>To keep your phone secure we recommend the following general measures:<\/p>\n<ul>\n<li>Install security updates on your phone regularly and promptly \u2013 whether it\u2019s a Google Pixel, an Android smartphone from a different manufacturer, or even an iPhone.<\/li>\n<li>Avoid installing apps from questionable sources.<\/li>\n<li>Read reviews before installing apps from official stores, since <a href=\"https:\/\/www.kaspersky.com\/blog\/ios-android-ocr-stealer-sparkcat\/52980\/\" target=\"_blank\" rel=\"noopener nofollow\">malware isn\u2019t uncommon there too<\/a>. Users who have already been burned will often sound the alarm in the reviews long before store moderators get around to removing the dangerous app.<\/li>\n<li>Install\u00a0<a href=\"https:\/\/me-en.kaspersky.com\/mobile-security?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____3d7d2c33c4c17a10\" target=\"_blank\" rel=\"noopener\">a reliable security solution<\/a>\u00a0to keep you from downloading malware, and warn you about suspicious activity on your device.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\"><input type=\"hidden\" class=\"placeholder_for_banner\" data-cat_id=\"premium-geek\" value=\"10102\">\n","protected":false},"excerpt":{"rendered":"<p>Google has released its September security update for Pixel smartphones \u2013 fixing 110 vulnerabilities. One of the vulnerabilities appears to be being used actively in targeted attacks.<\/p>\n","protected":false},"author":2726,"featured_media":26126,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1486],"tags":[105,22,45,121,268,2896],"class_list":["post-26125","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-android","tag-google","tag-smartphones","tag-updates","tag-vulnerabilities","tag-zero-day-vulnerabilities"],"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/google-pixel-september-2026-security-update\/26125\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/google-pixel-september-2026-security-update\/31094\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/google-pixel-september-2026-security-update\/30927\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/google-pixel-september-2026-security-update\/42764\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/google-pixel-september-2026-security-update\/56488\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/google-pixel-september-2026-security-update\/31095\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/google-pixel-september-2026-security-update\/36835\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/google-pixel-september-2026-security-update\/36504\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/vulnerabilities\/","name":"vulnerabilities"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=26125"}],"version-history":[{"count":1,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26125\/revisions"}],"predecessor-version":[{"id":26127,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26125\/revisions\/26127"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/26126"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=26125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=26125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=26125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}