Google Pixel phones exploited in 'targeted' zero-day attack
Key Points:
- Google confirmed that a limited number of Pixel phones were targeted by an actively exploited vulnerability related to the device's cellular modem, identified as CVE-2026-58704.
- The vulnerability allows a remote escalation of privilege without user interaction due to a logic error in the modem's code, enabling a "zero-click" attack.
- The September 2026 security update from Google patches over 200 vulnerabilities, including this critical modem issue, and users are urged to install the update immediately.
- The Cybersecurity and Infrastructure Security Agency (CISA) has labeled this a "known exploited vulnerability," highlighting its significant risk to federal networks and other targets.
- Details about the specific Pixel models affected and the nature of the exploitation remain unclear, but the attack appears to have been targeted rather than widespread.