Google Confirms Targeted Attacks Exploited a Pixel Modem Flaw

https://i.extremetech.com/imagery/content-types/00iD4a0fMzevWM4lHthNVvq/hero-image.fill.size_1200x675.png

Google has confirmed that some Pixel phones have been targeted in zero-day attacks due to a flaw in the cellular modem. Thankfully, the company fixed the issue in its September 2026 Pixel update, which began rolling out on Tuesday, September 15.

The vulnerability (CVE‑2026‑58704) has a CVSS severity score of 8.0 out of 10 and lets an attacker gain a higher level of access than most attacks, thanks to a logic error in the modem code. The worst part is that an exploit can occur without any user action or permission, allowing bad actors to take advantage of unwitting users remotely.

Google says there are indications that CVE‑2026‑58704 faces "limited, targeted exploitation" in the wild. The company hasn't shared how many Pixeldevices—or even which models—it believes have been affected. While similar attacks have been linked to commercial spyware vendors or state‑sponsored actors, no attribution exists for...

Copyright of this story solely belongs to www.extremetech.com. To see the full text click HERE

Read more