Mobile & Apps

Google Patches Pixel Modem Zero-Day Bug Exploited in Targeted Attacks

Google says CVE-2026-58704 was used in limited, targeted attacks against Pixel phones. The zero-click modem flaw could escape its sandbox and access broader device data; a patch issued September 16 protects users who install the latest update.

TechCrunch

Google has disclosed that a security vulnerability in its Pixel smartphones was exploited in limited, targeted cyberattacks, and has since issued a patch to address the flaw. The company announced the issue on Tuesday, September 16, 2026.

The bug, tracked as CVE-2026-58704, was found in the modem component of Pixel phones — the hardware and software that allows the device to connect to the internet. Exploiting the vulnerability could allow an attacker to break out of the modem’s sandboxed environment and gain access to broader data on the phone, a type of attack known as privilege escalation.

The flaw is particularly concerning because it can be exploited silently, without any action required from the phone’s owner. This type of attack is known as a “zero-click” exploit, meaning a victim does not need to tap a link or open a file to be compromised.

Google did not identify who was behind the attacks. A spokesperson did not respond to a request for comment. The company noted only that the bug “may be under limited, targeted exploitation.” Bugs of this nature are sometimes used by surveillance vendors — including spyware makers — who sell access to their software to governments and law enforcement agencies, though Google made no such attribution in this case.

The patch has now been issued, and Pixel owners should ensure their devices are running the latest software update to protect against the vulnerability.