Google says some Pixel phone owners were hacked in zero-day attacks
First reported by TechCrunch ·
Your Pixel phone is now protected from a silent, zero-click exploit that could expose your data.
Google has announced that some Pixel phone owners were targeted in zero-day attacks exploiting a vulnerability in the device's modem. The bug, identified as CVE-2026-58704, allowed attackers to escalate privileges from the modem's isolated environment into the broader phone data. This exploit could be performed silently through a "zero-click" attack, requiring no user interaction. Google has since patched the vulnerability. While Google did not disclose who was behind the attacks, such vulnerabilities are often exploited by surveillance vendors selling spyware to governments and law enforcement agencies. The company has not commented further on the specifics of the exploitation.
The exploitation of a modem vulnerability in Pixel phones highlights a critical area of mobile device security that is often overlooked. Attackers targeting the modem's connection capabilities, rather than user-facing applications, represent a sophisticated threat vector. This incident underscores the increasing complexity of cybersecurity threats and the need for robust, hardware-level security measures in addition to software patches.
This event is likely to increase scrutiny on modem security across all smartphone manufacturers and could spur further investment in secure modem firmware development. The potential for zero-click attacks necessitates a shift towards proactive threat hunting and more advanced endpoint detection and response solutions that can identify and mitigate such stealthy intrusions.
AI-written summary. May contain errors.