On September 15, Google released an update for Pixel smartphones to address a zero-day vulnerability identified as CVE-2026-58704 within the device's modem. The company noted that there were indications of its limited exploitation in targeted attacks.
This vulnerability allowed for privilege escalation, enabling attackers to break out of the modem's isolated environment and access other data on the device. According to TechCrunch, the exploit could be executed stealthily without any action required from the smartphone owner, such as clicking on a link or opening a file. Google has not disclosed the identity of the attackers who utilized this vulnerability.
The fix was included in the security patch released on September 5, 2026, and it will be available for all supported Pixel models.
