Attention Pixel phone users: Google announced that it has discovered a bug that allows malicious actors to access smartphone data without any action from the device owner. Google disclosed in a Pixel security bulletin that there are indications that the high-severity bug “may be under limited, targeted exploitation.”
The bug, with the catchy name of CVE-2026-58704, was found in the modem of Pixel phones. The modem is a bit of hardware that allows a device to connect with cellular networks and upload and download data. In an entry published to the National Vulnerability Database, Google noted that the bug could lead to “remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed.” Its bulletin also noted that “user interaction is not needed for exploitation.” That means the bug allows a malicious actor to break free of the modem environment to access data in the broader device, without any action from the victim.
Attacks that require no action from the victim are known as “zero-click.” They are especially insidious because even sophisticated users can fall prey to them, as they don’t rely on phishing tactics, and they can wreak havoc before a user is even aware they’ve been hacked, according to cybersecurity firm Check Point.
“Zero-click exploits are highly prized vulnerabilities by all cyber threat actors, including advanced persistent threats (APTs) and nation-states,” Check Point noted in a blog post. “They are commonly used to deliver spyware that secretly collects information on persons of interest to a government or other group.”
Google, however, did not disclose what types of users may have been targeted, how many, or what threat actor could be responsible. Google did not respond to Inc.’s request for comment.
Google’s Pixel security bulletin notes that its latest software update patches 110 vulnerabilities, of which the zero-click modem bug is one. According to information security outlet Bleeping Computer, 12 of the vulnerabilities entail remote code execution, and 89 of them entail privilege escalation, with severity levels of either critical or high. Security patches are available for supported Pixel devices, dating back to the Pixel 6a, although Pixel 5a and earlier devices are not eligible.
Google stated that users will receive a notification once the software update is ready to install, but they can also manually check their devices by going to “Settings” and “System and software update,” where they can view the status of their update. – Inc./Tribune News Service
