Pixel Phones Hit by Targeted Modem Attack, Patch Available Now
Google has confirmed that a limited number of Pixel phones were targeted in an attack related to the device's modem. The vulnerability, known as CVE-2026-58704, was patched in the September 2026 security update.
The issue is described as a possible permission bypass due to a logic error in the code, which could lead to remote escalation of privilege without any additional execution privileges needed. User interaction is not required for exploitation.
Exact details of how the vulnerability was exploited are unclear, but CISA notes that it was used on Pixel phones and was categorized as a 'known exploited vulnerability.' TechCrunch refers to this type of attack as a 'zero-click' exploit, which allows hackers to gain access without any user interaction.
The September 2026 patch fixes the issue, so users can update their devices to protect themselves. The incident serves as a reminder that even with robust security features, devices can still be vulnerable to targeted attacks.