Skip to content
Tech News
← Back to articles

Google says some Pixel phone owners were hacked in zero-day attacks

read original get Google Pixel 9 Pro → more articles
Why This Matters

Google confirmed that a zero-day vulnerability in the modem software of Pixel phones was actively exploited in targeted attacks, allowing attackers to escalate privileges beyond the modem sandbox without any user interaction. This matters because zero-click flaws are especially dangerous and often linked to surveillance vendors or spyware makers who target specific individuals, raising concerns about mobile security and privacy even for seemingly secure devices.

Key Takeaways
Worth a Look

Google Pixel 9 Pro — Staying current with the latest Pixel model means faster access to Google's security patches, like the one just released for this zero-day modem exploit. Keeping your device updated is one of the best defenses against zero-click attacks, and newer Pixels get priority support and updates directly from Google.

See Google Pixel 9 Pro on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

In Brief

Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks. The company said Tuesday that the bug, tracked as CVE-2026-58704, has now been patched.

According to the limited details about the vulnerability, the bug was found in Pixel phones’ modem, which lets the device to connect to the internet. Exploiting the bug could allow an attacker to gain access beyond the sandboxed walls of the modem and into the broader phone’s data, a vulnerability known as privilege escalation.

The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.

Google did not say who was exploiting the bug, and a spokesperson for Google did not return a request for comment. It’s not uncommon for bugs like this one to be abused by surveillance vendors, such as spyware makers, who sell access to their data-stealing software to governments and law enforcement agencies.