Google Patches Pixel Zero-Day Exploited in Targeted Attacks
Google has confirmed that a security flaw in its Pixel smartphones was exploited in real-world attacks before a patch was released. The vulnerability, tracked as CVE-2026-58704, was found in the phone's modem, the component that manages internet connectivity.
Exploiting the flaw allowed attackers to break out of the modem's isolated environment and access broader data on the device, a technique known as privilege escalation. Notably, the attack required no action from the victim, no clicking links or opening files, making it a 'zero-click' exploit that is especially hard to detect or avoid.
Google has not disclosed who carried out the attacks or how many users were affected, describing them as limited and targeted. Vulnerabilities like this are often associated with commercial spyware vendors that sell surveillance tools to government and law enforcement clients, though Google has not confirmed this in this case.