← Latest briefing

Technology

Google patches Pixel modem vulnerability exploited in targeted attacks

A zero-click flaw allowed privilege escalation, but Google has released a fix in its September update.

The short version

  • Google announced that a cellular modem vulnerability affecting Pixel smartphones was exploited in limited and targeted cyberattacks.[9to5Google · TechCrunch]
  • The flaw allows remote privilege escalation through a zero-click attack, requiring no interaction from phone owners to access device data.[TechCrunch]
  • Google issued a fix in its September 2026 security update, while CISA listed the flaw as a known exploited vulnerability posing risks to federal systems.[9to5Google · TechCrunch]
  • Google has not disclosed who was responsible for the exploits or which specific Pixel models were impacted.[9to5Google · TechCrunch]

Key facts

  • Google reported that a vulnerability in Pixel smartphones was exploited in limited, targeted cyberattacks.[9to5Google · TechCrunch]
  • The bug, tracked as CVE-2026-58704, resides in the cellular modem and permits remote privilege escalation beyond the modem's sandbox.[9to5Google · TechCrunch]
  • The security flaw can be exploited silently as a zero-click attack without user interaction.[9to5Google · TechCrunch]
  • Google resolved the flaw as part of its September 2026 security update, which addressed more than 200 security issues.[9to5Google · TechCrunch]
  • CISA added the bug to its known exploited vulnerabilities list, citing significant risk to the federal enterprise.[9to5Google]

What remains uncertain

  • Google did not disclose who was responsible for executing the attacks.[TechCrunch]
  • The exact details of how the vulnerability was exploited and which specific Pixel phone models were affected remain unclear.[9to5Google]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.