Google says some Pixel phone owners were hacked in zero-day attacks
Google patched CVE-2026-58704, a zero-click Pixel modem privilege-escalation zero-day exploited in limited, targeted attacks.
Google disclosed that a vulnerability in Pixel smartphones' modem software, tracked as CVE-2026-58704, was exploited in limited and targeted cyberattacks and has now been patched. Exploitation could allow an attacker to escape the modem sandbox and escalate privileges to access broader phone data. The bug can be exploited silently with zero user interaction. Google did not attribute the activity, though such modem bugs are commonly abused by surveillance vendors selling spyware to governments.