Technology
Google patches Pixel modem vulnerability exploited in targeted attacks
A zero-click flaw allowed privilege escalation, but Google has released a fix in its September update.
The short version
- Google announced that a cellular modem vulnerability affecting Pixel smartphones was exploited in limited and targeted cyberattacks.[9to5Google · TechCrunch]
- The flaw allows remote privilege escalation through a zero-click attack, requiring no interaction from phone owners to access device data.[TechCrunch]
- Google issued a fix in its September 2026 security update, while CISA listed the flaw as a known exploited vulnerability posing risks to federal systems.[9to5Google · TechCrunch]
- Google has not disclosed who was responsible for the exploits or which specific Pixel models were impacted.[9to5Google · TechCrunch]
Key facts
- Google reported that a vulnerability in Pixel smartphones was exploited in limited, targeted cyberattacks.[9to5Google · TechCrunch]
- The bug, tracked as CVE-2026-58704, resides in the cellular modem and permits remote privilege escalation beyond the modem's sandbox.[9to5Google · TechCrunch]
- The security flaw can be exploited silently as a zero-click attack without user interaction.[9to5Google · TechCrunch]
- Google resolved the flaw as part of its September 2026 security update, which addressed more than 200 security issues.[9to5Google · TechCrunch]
- CISA added the bug to its known exploited vulnerabilities list, citing significant risk to the federal enterprise.[9to5Google]
What remains uncertain
- Google did not disclose who was responsible for executing the attacks.[TechCrunch]
- The exact details of how the vulnerability was exploited and which specific Pixel phone models were affected remain unclear.[9to5Google]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.