Google Patches Actively Exploited Zero-Day in Pixel Modem
A critical authorization flaw in cellular hardware allowed for silent privilege escalation on targeted devices.

The 20-second version
- Vulnerability CVE-2026-58704 enabled 'zero-click' attacks via the device modem.
- The CISA has added the bug to its Known Exploited Vulnerabilities catalog.
- Google's September update addresses 109 total security issues across the Pixel ecosystem.
Why it matters
The vulnerability allowed attackers to bypass modem sandboxing without user interaction, turning a peripheral component into an entry point for full device data access.
The story
Google has released an emergency patch for a high-severity vulnerability, tracked as CVE-2026-58704, affecting the modem subcomponent of its Pixel smartphones. The company confirmed that the bug has been utilized in limited, targeted cyberattacks. The flaw is characterized as an improper authorization and protection mechanism failure that allows for privilege escalation.
Technical details indicate that the vulnerability is a 'zero-click' exploit, meaning it requires no action from the phone owner to succeed. Because the flaw resides in the cellular modem, attackers on an adjacent network can bypass security sandboxes to gain unauthorized access to the broader operating system and user data. The Cybersecurity and Infrastructure Security Agency (CISA) has formally recognized the risk, noting that such flaws are frequent vectors for state-sponsored or high-level malicious actors.
The September 2026 security bulletin also addresses a wider array of critical flaws beyond the modem. These include remote code execution (RCE) vulnerabilities in the IP Multimedia Subsystem (CVE-2026-55318), the Video Processing Unit (CVE-2026-56920), and the telephony stack. In total, 109 security issues were flagged, spanning components from the kernel and bootloader to the Trusted Execution Environment and fingerprint sensors.
While Google has confirmed 'targeted exploitation' in the wild, the company has not disclosed the identity of the affected users or the specific geographical regions where the attacks occurred. The lack of public information regarding the threat actor or their specific objectives is standard for early-stage zero-day disclosures to prevent further exploitation while patches are being deployed.
The 2026-09-05 patch level is now being pushed to all supported Pixel devices. Security researchers note that the complexity of the attack is low, meaning once the logic error in the modem's code was discovered, it could be reliably executed. The incident highlights ongoing security challenges in hardware-level components that operate outside the primary Android OS layer.
$3/1M in · $15/1M out
$7,200
$87,600 a year at this volume
The other side
Google has not provided evidence of widespread exploitation, suggesting the risk to the general public remains low compared to the specific high-value targets identified by current intelligence.
What's next
All Pixel owners are advised to verify their security patch level is dated September 5, 2026, or later. Federal agencies have been mandated to apply the update within a specific timeframe following the CISA notification.
Sources
- TechCrunchGoogle says some Pixel phone owners were hacked in zero-day attacks
- techcrunch.comGoogle says some Pixel phone owners were hacked in zero-day attacks
- 9to5google.comGoogle Pixel phones exploited in 'targeted' zero-day attack
- cyberinsider.comGoogle patches Pixel modem zero-day exploited in targeted attacks
- bleepingcomputer.comGoogle fixes actively exploited Android zero-day on Pixel devices
- securityaffairs.comGoogle Patches Pixel Modem Zero-Day Exploited in Targeted Attacks

Google Patches Actively Exploited Zero-Day in Pixel Modem
- • Vulnerability CVE-2026-58704 enabled 'zero-click' attacks via the device modem.
- • The CISA has added the bug to its Known Exploited Vulnerabilities catalog.
- • Google's September update addresses 109 total security issues across the Pixel ecosystem.
The Leverage Wire · www.theleveragewire.com/article/google-patches-actively-exploited-zero-day-in-pixel-modem






