Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Share
Google has released security patches to address a high-severity zero-day vulnerability in the cellular modem component of Pixel smartphones. The company confirmed that the flaw, tracked as CVE-2026-58704, has been subject to “limited, targeted exploitation.”
The vulnerability stems from a logic error in the modem code that allows for a permission bypass. This error could enable remote escalation of privilege, potentially affecting users in proximal or adjacent locations. Crucially, the flaw is a zero-click vulnerability, meaning it can be exploited without any user interaction.
Zero-Click Exploitation Risks
While Google has not attributed the exploitation to a specific threat actor, the nature of the attack is highly significant. The zero-click, modem-level characteristics of the flaw are consistent with tactics used by state-sponsored actors or commercial spyware vendors in targeted surveillance operations.
Broader Security Update for Pixel Devices
The modem fix is part of a wider security update for Pixel devices, which also includes the latest Android security patches. This release resolves more than 100 other vulnerabilities specifically affecting Pixel hardware and software.
Approximately 50 of these vulnerabilities have been rated with critical severity. These critical flaws affect several key components, including the multimedia subsystem, the bootloader, and the Trusted Execution Environment (TEE). Exploiting these vulnerabilities could allow attackers to achieve remote code execution (RCE), information disclosure, or denial of service (DoS).
Pixel users are advised to install the most recent system updates immediately to mitigate the risk of exploitation.




Leave a Reply