What is confirmed
Google's September Pixel bulletin says CVE-2026-58704 may be under limited, targeted exploitation; it does not provide a victim list.
The fix is included in security patch level 2026-09-05 for supported Pixel devices.
What it means
Zero-day means exploitation may have preceded a patch; it does not mean every Pixel phone is compromised.
A link reputation check cannot detect exploitation of a phone's internal component.
What to do
Open Settings, install the latest offered system update and check the resulting security patch level.
If your device is managed by an organisation or you suspect a targeted attack, contact its security team before wiping evidence.
Use the related SecurCheck tool, then confirm important decisions with an official source.



