
What was reported
Google's September Pixel bulletin states that there are indications CVE-2026-58704 may be under limited, targeted exploitation. This wording describes the vendor's assessment; it is not a claim of widespread compromise.
The bulletin says a security patch level of 2026-09-05 or later addresses its issues and those in the September Android bulletin on supported Google devices. The bulletin's publication date is 15 September, even though its URL contains September 1.
What to check
Check the device's installed patch level and available manufacturer updates. Verify the installed state after updating rather than assuming that receiving a notification completed the update.
Forensic focus
For devices already involved in an investigation, record the model, build and patch level and coordinate changes with the examiner. An update can change evidence. Device patch status alone cannot prove or disprove historical compromise.
Source published 15 September 2026. Briefing prepared 26 September 2026.