Pixel Modem Zero-Day Flaw Patched by Google Amid Spyware Fears
Google has patched a zero-day flaw in its Pixel phones' cellular modem that attackers may have exploited in targeted attacks. The vulnerability, CVE-2026-58704, allows a nearby attacker to escalate privileges without needing any user action or extra execution rights on the device.
The bug is located in the cellular modem and can be exploited via zero-click attacks. Google rated the flaw high severity and fixed it alongside 109 other Pixel vulnerabilities in its September update. Every supported Pixel device will receive the Sept. 5, 2026, patch level, which also covers the broader September Android bulletin.
Google's cautious wording suggests that the attack may be linked to commercial spyware vendors or state-backed hackers. Analysts noted that modem bugs draw extra attention because they operate below much of Android's app security model and handle a phone's traffic with carrier networks.