One of the 110 holes Google just patched on Pixel phones was already being used
Google publishes a phone security bulletin every month and most of them go by without comment. This one closes 110 flaws, and one of them was already being used on somebody before the fix existed.
CVE-2026-58704 sits in the cellular modem, the part of a phone that talks to the mobile network. A logic error there lets an attacker slip past a permission check and pick up privileges they should not have. Google's exact wording is that there are "indications that CVE-2026-58704 may be under limited, targeted exploitation", which in its house style tends to mean a handful of specific people rather than everyone. The attacker has to be adjacent on the network rather than anywhere on the internet, but the attack is low complexity and needs nothing from you at all: no tap, no link, no download. The rest of the bulletin includes 12 remote code execution flaws and 89 privilege escalation flaws rated critical or high.
This one is Pixel-only. Google's own handsets get a separate bulletin from the rest of Android because Google controls the hardware, so a Samsung or a Xiaomi is not waiting on this particular fix. On a Pixel, go to Settings, then Security and privacy, then System and updates, then Security update, tap Install and restart. When it comes back, the Android security update level should read 5 September 2026 or later. If it does not, the update has not reached your phone yet and it is worth looking again in a day or two.
Your phone is not what Tendvane looks after, but the habit is the same one it automates on the PC: its app updates through winget and its driver auto-update stop the software you never think about from quietly falling years behind.