Google Pixel Phones Hit by Zero-Click Attacks: CVE-2026-58704 Exploited in Wild
Google Pixel phone users are at risk of zero-click attacks due to an improper authorization bug in their cellular modems. The vulnerability, tracked as CVE-2026-58704, was disclosed by Google on Tuesday and can be exploited with no user interaction required.
The bug allows attackers to bypass permission checks and escalate privileges, posing a significant risk to the federal enterprise, according to the US Cybersecurity and Infrastructure Security Agency (CISA).
CISA added the CVE to its Known Exploited Vulnerabilities Catalog on Wednesday and gave federal agencies three days - until September 19 - to patch the flaw.