Google has released a major security update for its Pixel devices, addressing 110 vulnerabilities. This update is crucial for maintaining the security of devices such as the Pixel smartphones and tablets. Among these, one vulnerability, identified as CVE-2026-58704, has already been exploited in targeted attacks. Google advises Pixel users to install the September update as soon as possible to protect their devices. The vulnerability affects the cellular modem, which is the component responsible for connecting to mobile networks. It results from a logic error in how the modem handles permissions. If exploited, this flaw could allow an attacker to bypass these permissions and gain higher access to the device without requiring any action from the user, such as clicking on a link or downloading an app. However, the vulnerability cannot be exploited remotely over the internet. Instead, it requires "adjacent" access to the target's network, such as being in the same physical location or on the same local network. This means that while the risk is limited for widespread attacks, targeted individuals or groups could still be at risk. In addition to CVE-2026-58704, the September update also fixes 12 vulnerabilities that could allow remote code execution and 89 that could lead to privilege escalation. Many of these are classified as critical or high severity, highlighting the importance of the update. Google has not provided details on the specific methods used in the observed attacks or the identities of those affected or responsible. However, it is clear that the update is a significant step in securing Pixel devices against potential threats. Users can apply the update by going to their device's Settings, navigating to Security and Privacy, then System and Updates, and selecting the Security Update option. After installing the update, users should restart their device to ensure the changes take effect. This update is being rolled out to all supported Pixel devices, emphasizing the need for users to stay current with security patches to protect their personal data and device integrity.