Google disclosed that a vulnerability in Pixel phones' modem software, tracked as CVE-2026-58704, was exploited in a limited number of targeted attacks before being patched this week. The flaw allowed attackers to escalate privileges from the isolated modem component into the phone's broader system without any user interaction, a so-called zero-click exploit. Google has not identified who carried out the attacks.
techcrunch.com
· 2026-09-16
Google's September 2026 security bulletin fixes 110 vulnerabilities in Pixel devices, including a high-severity flaw (CVE-2026-58704) in the Cellular Modem component that is being exploited in limited, targeted attacks. The bug stems from a logic error that lets an attacker on an adjacent network bypass permissions and escalate privileges without user interaction. The update, rolling out at patch level 2026-09-05, also addresses 12 critical remote code execution bugs and 89 privilege escalation issues.
bleepingcomputer.com
· 2026-09-16