π¨ Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
β
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
β
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
β
Google has not disclosed:
β’ Who carried out the attacks
β’ How many Pixel owners were targeted
β’ How the victims were selected
β’ What tools or spyware may have been deployed
β
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
β
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.






