Google’s September security update for Pixel phones landed on 15 September fixing something more urgent than the usual monthly patch list: CVE-2026-58704, a privilege escalation flaw in the cellular modem that Google itself says “may be under limited, targeted exploitation.” The flaw affects every supported Pixel from the 6 series through to the newest 11 family, and it needs no user interaction at all. No dodgy link, no downloaded app, nothing clicked. A nearby attacker can exploit it at the modem level before the phone’s operating system even gets involved.
Google hasn’t named who’s behind it, but a zero-click, proximity-based modem exploit that only shows up in “limited, targeted” attacks has the fingerprints of the kind of tooling normally associated with commercial spyware vendors, not opportunistic criminals. That’s actually useful context for a small business: this isn’t a mass phishing campaign hitting every inbox in the country. It’s the kind of flaw more likely to be aimed at specific people, which still matters if any of your staff, especially anyone senior, client-facing, or handling sensitive deals, carries a company or BYOD Pixel phone.
Update now, don’t wait for it to queue itself
If your business issues Pixel devices, or allows staff to use personal Pixels for work email and messaging, the fix is simple and already available: install the September security update immediately rather than letting it sit in the background. For a business of any size, this is a good moment to check whether device updates are actually being applied consistently, or whether they’re something individual staff members are expected to remember on their own. If you don’t have a mobile device management (MDM) tool forcing updates across company phones, a flaw like this is exactly the argument for getting one.
BYOD makes this everyone’s problem, not just IT’s
Most UK SMEs don’t issue company phones to every employee, which means a meaningful chunk of the devices connecting to your email, your calendar, and your shared drives are personal handsets you have no direct control over. A zero-click modem exploit doesn’t care whose name is on the phone contract. If you allow BYOD, this is worth a short, plain-English reminder to staff this week: check for a pending Android security update, install it, and don’t postpone it. It costs nothing and takes five minutes.
This is also a useful trigger to ask a broader question: does anyone in your business actually know which devices are being used to access company systems, and whether they’re patched? For most small businesses the honest answer is no, and that’s a monitoring gap rather than a technology problem. Keeping continuous visibility over the devices, accounts, and exposure points connected to your business, rather than finding out only after something goes wrong, is exactly the kind of ongoing oversight services like KeepSafe are built around.
Don’t panic, but don’t ignore it either
To be clear: this is not a reason to abandon Android or Pixel devices, and the “limited, targeted” language from Google strongly suggests most businesses were never the intended target. But zero-click, no-interaction vulnerabilities are the ones security teams worry about most precisely because there’s no user behaviour to train around. You can teach staff not to click suspicious links. You can’t teach a phone to avoid being near an attacker’s equipment.
The takeaway
Google patched a serious, zero-click Pixel modem flaw on 15 September that’s already seen limited real-world exploitation. If your business has Pixel phones in circulation, company-owned or BYOD, get the September update installed this week rather than assuming it will happen automatically. And if this is the first time you’ve thought about whether your business actually has visibility over which devices connect to your systems and whether they’re up to date, treat that as the real takeaway, not just this one patch.