Google Says Some Pixel Phone Owners Were Hacked in Zero-Day Attacks
Google disclosed that a zero-day flaw in Pixel phone modems was exploited in limited, targeted cyberattacks. The vulnerability, tracked as CVE-2026-58704, allowed privilege escalation beyond the modem sandbox. The company released a patch on Tuesday.
What the vulnerability allowed attackers to do
The flaw resided in the modem software that handles internet connectivity on Pixel devices. Successful exploitation granted attackers access outside the modem’s sandboxed environment and into the rest of the phone’s data. The attack required no user interaction, classifying it as a zero-click exploit. The bug was tracked under the identifier CVE-2026-58704 and affected the component responsible for cellular and data connections.
How the attacks were carried out
Google stated the bug was used in “limited and targeted” operations. No details were provided on the victims’ identities or the scale of the campaign. The company did not identify the actors responsible and did not respond to further questions after the disclosure on Tuesday. The attacks were described as silent, requiring nothing from the device owner.
Who might be behind such exploits
Zero-day flaws of this type are frequently purchased and deployed by commercial surveillance vendors. These firms sell access to governments and law enforcement agencies for spyware operations. Google offered no confirmation that spyware was involved in the observed attacks and provided no information on the identity of the threat actors.
Patch availability and user actions
The security update addressing CVE-2026-58704 has been issued. Pixel owners should install the latest software version through the device settings menu to close the vulnerability. The patch resolves the privilege-escalation issue in the modem firmware and prevents further exploitation of the zero-click vector.
Conclusion
Google’s advisory marks another instance of a zero-day being actively used against its devices before a fix was available. Owners are encouraged to apply updates promptly to reduce exposure to similar modem-based attacks.
Frequently asked questions
Which Pixel models were affected?
Google did not list specific models. The advisory applies to devices running vulnerable modem firmware prior to the September 2026 patch.
Did the attacks require any user action?
No. The exploit was zero-click, meaning victims did not need to open links or files.
Is the flaw still active?
The patch is now available. Devices that remain unpatched remain exposed to the reported attack vector.
Energy Outlook Dispatch