Google patches Pixel modem zero-day used in targeted attacks

Google has patched a zero-day vulnerability in Pixel phone modems that was exploited in limited, targeted attacks. The flaw, tracked as CVE-2026-58704, could allow an attacker to gain elevated access to the device without any user interaction. Google did not say who was behind the attacks, but such bugs are often used by spyware vendors.
The vulnerability resides in the modem component of Pixel devices, which handles cellular and internet connectivity. Because the flaw allows privilege escalation, an attacker could break out of the modem’s isolated environment and access sensitive data stored elsewhere on the phone. Google’s advisory notes the exploit requires no user action, classifying it as a zero-click attack, and the company has already released a patch to address it.
While Google has not identified the attackers, the technical characteristics align with tactics commonly employed by commercial spyware vendors. These firms often sell such zero-click exploits to government clients for surveillance purposes. The limited, targeted nature of the attacks suggests a deliberate campaign rather than broad, indiscriminate hacking, though Google has not disclosed which specific Pixel models or Android versions were affected.
This patch highlights the persistent threat of zero-click vulnerabilities in widely used consumer devices. For Pixel owners, the risk is real but likely limited to high-value targets, such as journalists or activists, given the cost and sophistication of such exploits. The incident may push users to update promptly, but it also underscores how even major manufacturers can be caught off guard, potentially eroding trust in mobile security if similar flaws emerge more frequently.