Google says some Pixel phone owners were hacked in zero-day attacks
Google disclosed that a software flaw in the modem of some Pixel smartphones was used in limited, targeted cyberattacks and has been patched. The company identified the issue as CVE-2026-58704 and said the vulnerability could allow attackers to break out of the modem's sandbox and access broader phone data.

Why It Matters
A zero-click privilege-escalation exploit in a phone modem can give attackers remote access without any user interaction, raising serious privacy and security risks for affected devices. Vulnerabilities of this type are frequently abused by commercial spyware vendors that sell access to governments and law enforcement.
Key Facts
- vulnerability identifier: CVE-2026-58704
- affected component: Pixel phones' modem
- attack scope: limited, targeted exploitation
- attack type: zero-click privilege escalation
- patch status: Google says the bug has been patched
Google announced that a bug in the modem software of some Pixel smartphones was exploited in a small number of targeted attacks and that the issue has been fixed. The company assigned the flaw the identifier CVE-2026-58704 and said a patch is now available. According to Google, the defect lies in the modem subsystem, which handles the phone's network connectivity. Exploitation could allow an attacker to escape the modem's isolated environment and gain elevated privileges into other parts of the device and its data. The company said the vulnerability can be abused without any action by the phone owner in what is known as a "zero-click" attack, meaning victims do not need to tap a link or open a file for the exploit to succeed. Google did not identify who carried out the attacks, and a company spokesperson did not respond to a request for comment. The company also noted that vulnerabilities like this are often abused by surveillance vendors that develop and sell spyware to governments and law enforcement agencies.
Keep Reading

Robots are waiting for a ChatGPT moment: Nvidia’s Les Karpas explains why at TechCrunch Disrupt 2026

A stolen coin can be returned. A leaked identity cannot.

AI Pause Would Help Dominant Firms, Not Safety, Think Tank Warns
