Google Pixel Phones Hit by Zero-Click Attack: Update Now
Google has disclosed a high-severity security flaw affecting the cellular modems in its Pixel phones, tracked as CVE-2026-58704. The vulnerability allows attackers to bypass permission checks and escalate privileges without any user interaction, meaning a device could be compromised without the owner clicking a link or opening a file. Google has confirmed the flaw may already be under limited, targeted exploitation, though details on how attackers are using it remain scarce.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities Catalog and given federal agencies just three days to patch it, underlining how seriously the issue is being treated. Zero-click attacks like this are frequently associated with commercial spyware operators who target specific individuals rather than the general public, but any unpatched device remains at risk regardless of who is behind the exploit.
This follows recent CISA warnings about two separate Chromium browser vulnerabilities, also added to its exploited vulnerabilities list, which have reportedly been chained together by espionage groups to breach organisations in the US and Southeast Asia. Together, these incidents highlight a pattern of attackers actively exploiting flaws in widely used devices and browsers before many users have had a chance to patch.