Who Patches the Phones?
Google fixed a flaw in the Pixel's cellular radio and said it may already be in use. It's probably not your phone. The question it raises is who would have installed the fix if it were.
On September 15, Google published its monthly bulletin for Pixel phones — 122 fixes. One carried a sentence Google does not write often: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation." That one is in the modem — the part of the phone that talks to the cell network. The next day it went on the US government's list of flaws criminals are actively using, with a three-day federal deadline. Now the honest part: it's a Pixel flaw. Most of your people don't carry one. But answer this one anyway: if it had been your phone, who would have installed the fix? The technical part — you can skip this box Google Pixel Update Bulletin, published September 15, 2026, covering 122 issues. CVE-2026-58704 sits in the Modem subcomponent, rated High , described by Google as a permission bypass arising from a logic error. Google's wording on exploitation, verbatim: "There are indications that CVE-2026-58704 may be under limited, targeted exploitation." Security patch level 2026-09-05 or later contains the fix ; earlier patch levels do not. All supported Pixel devices receive the 2026-09-05 level. The flaw was added to the Known Exploited Vulnerabilities catalog kept by CISA, the Cybersecurity and Infrastructure Security Agency, on September 16, with a September 19 remediation deadline for federal civilian agencies — that catalog could not be read directly for this article and the dates come from two independent reports, by Ravie Lakshmanan at The Hacker News and Aminu Abdullahi at TechRepublic. Both describe the flaw as requiring no action from the phone's owner; Google's bulletin does not characterise it either way, so we're attributing that rather than asserting it. What that actually means The modem is a computer of its own. Your screen and apps run on one processor; the cellular radio runs on another, with its own software, updated by the same monthly patch. A flaw there needs no tap from you — the radio listens whether you do or not. "Security patch level" is a date, not a version number, and it's the one that matters. A phone can run the newest Android and still be months behind. 2026-09-05 or later is fixed. "Limited, targeted exploitation" means what it says: somebody is using this against specific people, not everybody. Not a reason to panic. A reason the fix got a deadline. The question underneath Your laptops and servers get patched because somebody is paid to. There's a schedule, and a machine falling behind shows up somewhere. The phone your office manager reads company email on gets patched when she notices the prompt, usually while doing something else, often by pressing "remind me tomorrow." No schedule, no list. Eight months behind and nothing says so. That phone has your email, probably your calendar, a saved password or two, and quite possibly the authenticator app guarding everything else. It's one of the most sensitive devices in your business and the only one with no owner. Worth saying where we sit, because it cuts against us: we don't manage or patch client phones. It isn't a service we offer, so there's nothing at the end of this we're selling. For most small-business agreements, ours included, the phones sit outside what's covered — a line somebody drew years ago, for good reasons, that nobody has looked at since. Looking at it is free. What to do, and the first two take ten minutes Check your own phone's security patch date. On Android: Settings → Security & privacy → System & updates → Security update. iPhones have no separate patch date — Settings → General → Software Update tells you what you're on. Turn on automatic updates while you're there. Then write the list. Which phones read company email? Personal or company-owned, doesn't matter. Most businesses your size can't answer that. The list takes an afternoon and never needs building again. Then decide, on purpose, whether they're in scope. Not "should we buy something." Just: are these devices somebody's responsibility, or nobody's? Both are legitimate answers. Only one is a decision.