Industry News

Google Patches Pixel Zero-Day Exploited in Targeted Attacks

TechCrunch · 16 Sept 2026
Key Takeaway Ensure all company and staff mobile devices, especially Pixel phones, are updated immediately to the latest software version to close this vulnerability.

Google has confirmed that a security flaw in its Pixel smartphones was exploited in real-world attacks before a patch was released. The vulnerability, tracked as CVE-2026-58704, was found in the phone's modem, the component that manages internet connectivity.

Exploiting the flaw allowed attackers to break out of the modem's isolated environment and access broader data on the device, a technique known as privilege escalation. Notably, the attack required no action from the victim, no clicking links or opening files, making it a 'zero-click' exploit that is especially hard to detect or avoid.

Google has not disclosed who carried out the attacks or how many users were affected, describing them as limited and targeted. Vulnerabilities like this are often associated with commercial spyware vendors that sell surveillance tools to government and law enforcement clients, though Google has not confirmed this in this case.

Google Pixel zero-day mobile security spyware vulnerability

Summarised by CISO AI from TechCrunch. We link back to every original so you can read it yourself.