Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Google Patches Critical Pixel Modem Zero-Day Exploited in Attacks

Published 16 September 2026

Google has patched a critical zero-day vulnerability in its Pixel smartphones that was exploited in limited, targeted attacks requiring no user interaction. The flaw, tracked as CVE-2026-58704, resides in the Pixel's cellular modem and allows for remote privilege escalation, potentially granting an attacker access to the device's core functions. The company disclosed the issue in its September 2026 security advisory, stating there were indications the vulnerability may have been under limited, targeted exploitation. Google did not identify the attacker, the number of devices targeted, or the specific objectives of the attacks. The vulnerability is classified as high severity with a CVSS score of 8.0. According to the advisory, the flaw is a permission bypass caused by a logic error in the modem code. This could lead to remote, proximal-adjacent escalation of privilege with no additional execution privileges needed. Crucially, user interaction is not required for exploitation, making it a zero-click attack. The attack vector is adjacent, meaning an attacker would need to be within a proximal network range to reach the vulnerable modem environment.

0:00 / 0:00