Google says some Pixel phone owners were hacked in zero-day attacks
Google patched CVE-2026-58704, a zero-click Pixel modem privilege-escalation zero-day exploited in limited, targeted attacks.
Google disclosed that a vulnerability in Pixel smartphones' modem software, tracked as CVE-2026-58704, was exploited in limited and targeted cyberattacks and has now been patched. Exploitation could allow an attacker to escape the modem sandbox and escalate privileges to access broader phone data. The bug can be exploited silently with zero user interaction. Google did not attribute the activity, though such modem bugs are commonly abused by surveillance vendors selling spyware to governments.
- CVE-2026-58704 is a modem flaw enabling sandbox escape and privilege escalation on Pixel phones
- Zero-click exploitation requires no victim interaction
- Patched by Google as of the September 2026 Pixel update
- Attribution not disclosed; surveillance vendor abuse considered likely
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58704 | Permission Bypass in Google Pixel Cellular Modem Allows Proximal Privilege Escalation A logic error in the cellular modem component causes an improper authorization check (CWE-285/CWE-693), allowing a permission bypass. An attacker who already has low privileges and is on an adjacent network (proximal, e.g., a hostile local or cellular-adjacent network) can trigger the flaw without any user interaction, and successful exploitation yields remote escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.0). The flaw was assigned through Google's device security CNA ([email protected]), consistent with modem firmware shipped in Google Pixel-class devices; specific affected firmware versions were not provided in the source data. No public proof-of-concept is known, the issue is not listed in CISA's KEV catalog, and there is no evidence of exploitation in the wild. Defenders should treat this as a patch-on-next-bulletin item unless devices operate in high-risk adjacent-network environments. Do: Install the latest Google monthly security update that includes the cellular modem firmware patch and verify the device's security patch level reflects it. Because exploitation requires network adjacency plus some existing privilege, prioritize devices used in high-risk or shared-network settings and watch for indicators of rogue femtocell/base-station or hostile local-network activity. With no public PoC or KEV listing, standard monthly patch cadence is reasonable outside those high-risk scenarios. | 8.8 | — | KEV |
| masstens of millions of devices (≈10M+ active Pixel-class handsets worldwide) |
Full article175 words · extracted from techcrunch.com · click to collapse
Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks. The company said Tuesday that the bug, tracked as CVE-2026-58704, has now been patched.
According to the limited details about the vulnerability, the bug was found in Pixel phones’ modem, which lets the device to connect to the internet. Exploiting the bug could allow an attacker to gain access beyond the sandboxed walls of the modem and into the broader phone’s data, a vulnerability known as privilege escalation.
The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.
Google did not say who was exploiting the bug, and a spokesperson for Google did not return a request for comment. It’s not uncommon for bugs like this one to be abused by surveillance vendors, such as spyware makers, who sell access to their data-stealing software to governments and law enforcement agencies.
Text extracted automatically; images, tables and formatting may be missing. Original: https://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/