· via TechCrunch
Google patches Pixel zero-day CVE-2026-58704 exploited in targeted zero-click attacks
Google says a zero-click Pixel modem flaw tracked as CVE-2026-58704 was exploited in limited, targeted attacks against some owners, and has shipped a patch.

Google confirms in-the-wild exploitation
Google has confirmed that a software flaw in its Pixel smartphones was actively exploited, and that a fix has already been released. According to a TechCrunch report published on September 16, the company said on Tuesday that the vulnerability, tracked as CVE-2026-58704, was abused in a small number of targeted attacks against Pixel owners.
Few technical details have been made public. What is known is that the flaw resides in the Pixel's modem, the component that handles the phone's connection to cellular networks and the internet. According to the information released so far, exploiting the bug let an attacker escape the confines of the modem's sandbox and reach data stored elsewhere on the device. In security terms this is a privilege escalation: code that should have been trapped inside a restricted environment gains access to resources it was never meant to touch.
A zero-click flaw
The most troubling detail is how the bug could be triggered. TechCrunch reports that exploitation required no interaction from the phone's owner. The victim did not need to tap a link, open an attachment or install anything — an approach known as a zero-click attack.
That property makes flaws like this one especially dangerous. Traditional phishing-style attacks depend on a user making a mistake; a zero-click modem bug can in principle compromise a phone before the owner has any chance to notice something is wrong.
No attribution, but a familiar pattern
Google did not identify who was behind the attacks, and a company spokesperson did not respond to TechCrunch's request for comment. The publication notes that vulnerabilities of this kind are frequently purchased and weaponised by commercial surveillance vendors, which sell spyware to government and law-enforcement customers.
That remains context rather than attribution. Still, the shape of the incident — a silently exploitable modem flaw used against a narrow set of victims — matches the profile of mercenary spyware campaigns more closely than opportunistic criminal hacking, which tends to cast a far wider net.
Why it matters
A zero-click privilege escalation in a modem sits among the most serious classes of mobile vulnerability. The modem is a natural attack surface because it processes untrusted network traffic before a user does anything at all, and a breakout from it opens a path into the wider phone.
For Pixel owners the practical takeaway is straightforward: a patch exists, and installing it promptly closes off a route that attackers demonstrably used. The incident is also a reminder of how much value the underground and commercial markets place on mobile zero-days. Bugs of this type are prized precisely because they bypass both user vigilance and sandboxing, and buyers have every incentive to keep them secret — which means the gap between private discovery, quiet exploitation and eventual patching can stretch a long time, and the true number of victims is rarely known even after a fix ships.
Google's decision to confirm exploitation publicly, while unusual, gives defenders and users information they would otherwise never receive.
- #google-pixel
- #security
- #zero-day
- #android
- #vulnerability