Google announced that some Pixel phone owners were targeted in cyberattacks exploiting a vulnerability in the devices’ modem software. The bug, tracked as CVE-2026-58704, has been patched.
The vulnerability resides within the Pixel phones’ modem, the component responsible for connecting the device to the internet. Successful exploitation could allow attackers to escalate privileges, gaining access to data beyond the modem’s isolated environment. Google characterized the exploit as a “zero-click” attack, meaning it requires no interaction from the phone owner – such as clicking a link or opening a file – to function.
Google did not disclose who was exploiting the vulnerability, and a spokesperson did not respond to a request for comment. The company noted that bugs of this nature are often leveraged by surveillance vendors who sell data-stealing software to governments and law enforcement agencies.
Read the original coverage
💬 Comments
📜 Comment Policy