Google Pixel modem flaw exploited via zero-click attacks
Google has confirmed that a zero-day flaw in the cellular modems of its Pixel phones has been actively exploited in targeted attacks, with no user interaction required to compromise a device. The vulnerability, an improper authorisation bug that lets attackers bypass permission checks and escalate privileges, matters because such "zero-click" flaws are commonly favoured by commercial spyware vendors to covertly surveil specific individuals. Google has now issued a fix, but details remain scarce beyond the confirmation of exploitation.
The flaw, tracked as CVE-2026-58704, was disclosed by Google on Tuesday and rated high-severity, with the company warning it "may be under limited, targeted exploitation." The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities Catalog on Wednesday, giving federal agencies just three days, until 19 September, to patch it. The disclosure follows CISA's addition earlier this month of two Chromium V8 engine flaws, CVE-2026-85046 and CVE-2026-87491, which security firm Proofpoint said were chained together by at least four suspected China-linked espionage groups to breach networks in the US and Southeast Asia.
- Pixel modem zero-day exploited in zero-click attacks, now patched
- CISA gives US federal agencies until 19 September to fix it
- Follows separate Chromium bugs exploited by China-linked hacking groups