Google recently patched a zero-day vulnerability in Pixel phones that was exploited in targeted attacks. The flaw, tracked as CVE-2026-58704, affects the phone’s modem component and could lead to remote privilege escalation with no additional execution privileges needed.
The vulnerability has been rated high severity by Google, which is aware of “limited, targeted exploitation”. This suggests that the attack may have been carried out by a specific threat actor or group, possibly commercial spyware vendors or state-sponsored actors. The modem-level, zero-click nature of the flaw is also consistent with past attacks attributed to these types of actors.
The latest Pixel updates not only patch this vulnerability but also resolve over 100 other vulnerabilities that are specific to Pixel devices. Nearly 50 of these vulnerabilities have critical severity, enabling remote code execution or privilege escalation. The critical flaws affect various components, including the multimedia subsystem, VPU, and bootloader. Most of the remaining vulnerabilities are high severity, and exploiting them can lead to remote code execution, privilege escalation, information disclosure, and denial of service (DoS).
The fact that this vulnerability was exploited in targeted attacks is particularly concerning, as it suggests that the attackers may have had specific goals or interests in mind. Targeted attacks often involve sophisticated tactics and are typically carried out by well-resourced actors.
It’s worth noting that the Pixel updates also include the most recent Android security patches, which address a wide range of vulnerabilities across various components. This highlights the importance of keeping devices up to date with the latest security patches to prevent exploitation by attackers.
For users, this serves as a reminder to prioritize device security and keep their phones updated with the latest software. Regularly checking for updates and installing them promptly can help mitigate the risk of exploitation by attackers.
Source: SecurityWeek — 2026-09-16