Pixel Owners Vulnerable to Zero-Click Hacking Flaw
A previously unknown flaw in Google's Pixel smartphones allowed hackers to access sensitive information without requiring any user interaction.
The vulnerability, known as CVE-2024-58704, was discovered in the modem of affected devices and enabled a 'zero-click' attack that bypassed traditional security measures.
According to Google's September security bulletin, a small number of Pixel owners were hacked using this method, which remained invisible to users.
The attackers exploited a logic error in the modem's code to escape its sandbox and access sensitive data, and were likely positioned near their targets or connected to the same network.
Google has confirmed that the patch for this flaw was released with the September update, but notes that it's 'limited and targeted' exploitation, suggesting that commercial spyware may have been involved.