Google patched a flaw in its Pixel phones' cellular modem that attackers may have exploited in zero-click attacks, part of a September update fixing 110 vulnerabilities.
Key Points:
- Google warned that CVE-2026-58704 in the Pixel cellular modem may be under limited, targeted exploitation.
- The zero-click flaw needs no user action and can let a nearby attacker escalate privileges.
- Supported Pixel devices will receive the Sept. 5, 2026, patch level, which fixes 110 vulnerabilities.
Google Pixel Modem Zero-Day
The company flagged the bug, tracked as CVE-2026-58704, in its Pixel Update Bulletin on Tuesday. Google said there are indications the flaw may be under limited, targeted exploitation, and it urged all customers to accept the new update on their devices as soon as possible.
The vulnerability sits in the cellular modem, the component that lets a phone connect to mobile networks and the internet. A logic error in the modem code can allow a permission bypass, which could let a nearby attacker escalate privileges without needing any extra execution rights on the device. No user interaction is needed.
A target does not need to click a link or open a malicious file for an intrusion to succeed. Google rated the flaw high severity and fixed it alongside 109 other Pixel vulnerabilities, and every supported device is due to receive the Sept. 5, 2026, patch level, which also covers the broader September Android bulletin.
Also Read: Bitcoin Mining Faces 50% Hashrate Gap While AI Draws Capacity
Pixel Spyware Attack Risk
Google has not named the attackers, the victims or the person who found the flaw, and it has not said when the attacks began, while a company spokesperson did not respond to a request for comment.
The pattern looks familiar. Analysts noted that the zero-click, modem-level nature of the bug and Google's cautious wording match past attacks linked to commercial spyware vendors or state-backed hackers. Such vendors often sell their data-stealing tools to governments and law enforcement agencies, though nothing in Google's advisory ties this case to any specific group.
Modem bugs draw extra attention. They operate below much of Android's app security model and handle a phone's traffic with carrier networks, so attackers can use them to reach privileged access without malicious apps or phishing links, security researchers explained.
The Pixel fix follows a June patch for CVE-2025-48595, an Android Framework zero-day that Google addressed after its use in targeted attacks, which could let hackers run code and gain higher privileges on devices running Android 14 or later.
Read Next: Shiba Inu Fixes Shibarium's Broken Wallet Link, But SHIB Slides 6% In A Week

