// 9TO5GOOGLE — MOBILE & WEB
Google confirms Pixel phones were exploited in ‘targeted’ attack related to modem
Google has confirmed that a “limited” number of Pixel phones were attacked by a vulnerability related to the modem on the device.
As part of the September 2026 security update, Google patched over 200 security vulnerabilities, but specifically calls out that one of those was actively exploited in the wild.
Note: There are indications that CVE-2026-58704 may be under limited, targeted exploitation.
The issue is related to the modem, with a bypass that requires no user interaction. CVE-2026-58704 is described as follows:
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Exact details of how the vulnerability was exploited are unclear – as well as which models were affected – but CISA (via The Hacker News) says that it was exploited on Pixel phones, explaining that “Google Pixel devices contain an improper authorization vulnerability in the cellular modem.” Combined with Google’s announcement, this was used in the wild, apparently to hack “targeted” devices. CISA issued a notice that this is a “known exploited vulnerability,” explaining that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” TechCrunch notes that this is called a “zero-click” attack, adding that Google hadn’t replied to a request for comment around the vulnerability being exploited and who was exploiting it.
If you’re on a Pixel phone, updating to the September 2026 patch, rolling out now, fixes the issue.
Follow Ben: Twitter/X, Threads, Bluesky, and Instagram
FTC: We use income earning auto affiliate links. More.