Google has confirmed a serious flaw in its Pixel smartphones was exploited in real-world attacks before the company fixed it, and the vulnerability—tracked as CVE-2026-58704—was patched on September 16, 2026.
The flaw was located in the modem software of Pixel phones, the component that connects the device to cellular networks and the internet. Modems are normally run in an isolated sandbox to prevent compromises there from reaching the rest of the operating system and personal data. According to limited technical details released with the fix, exploiting CVE-2026-58704 allowed an attacker to escape that modem sandbox and access broader data on the device, a type of privilege escalation bug.
Pixel security bug: technical details
Security notes released by Google indicate the vulnerability could be triggered silently as a zero-click exploit, meaning victims did not need to click a link, open a file or install an app for the attack to succeed. Google provided only limited technical information alongside the patch, describing the bug as a pathway for attackers to elevate privileges from the modem environment into the wider device.
Scope, impact and Google response
Google said the exploitation was limited and targeted rather than a mass-scale campaign, and explicitly confirmed that some Pixel owners were hacked using the vulnerability before the patch became available. The company addressed the issue as part of its Tuesday security update and says the bug has been patched as of September 16, 2026. Google has not publicly identified who exploited the flaw, and a company spokesperson did not respond to a request for comment on attribution.
The disclosure does not specify how long the flaw was active before being discovered. Zero-day bugs affecting mobile modems are commonly linked by security researchers to surveillance vendors and spyware makers, but Google’s announcement does not confirm such a connection in this case.
For users, the practical takeaway is direct: installing the September update closes this specific hole. Google has not disclosed exactly how many people were affected or who was responsible for the targeted attacks.

