Vulnerabilities

Google Pixel zero-day CVE-2026-58704: install the September update

Google reports indications of limited, targeted exploitation of CVE-2026-58704. The September Pixel security update addresses the flaw.

Conceptual illustration: Google Pixel zero-day CVE-2026-58704: install the September update
Conceptual illustration · SecurCheck

What is confirmed

Google's September Pixel bulletin says CVE-2026-58704 may be under limited, targeted exploitation; it does not provide a victim list.

The fix is included in security patch level 2026-09-05 for supported Pixel devices.

What it means

Zero-day means exploitation may have preceded a patch; it does not mean every Pixel phone is compromised.

A link reputation check cannot detect exploitation of a phone's internal component.

What to do

Open Settings, install the latest offered system update and check the resulting security patch level.

If your device is managed by an organisation or you suspect a targeted attack, contact its security team before wiping evidence.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Google — Pixel Update Bulletin, septembre 2026