Google has recently confirmed evidence that spyware exploited a security vulnerability in the Pixel modem firmware to mount attacks. Because the attacks occurred before Google had fixed the flaw, this incident falls within the realm of a zero-day vulnerability. Moreover, the attackers employed a zero-click exploit.
The CVE-2026-58704 Vulnerability
In the changelog, Google notes that CVE-2026-58704 may have come under targeted, limited exploitation by attackers. The vulnerability resides in the modem and likely constitutes a security defect within the modem firmware. Modem firmware has caused a great many security problems in the past. Most such flaws are never unearthed and exploited by hackers, but when one is successfully discovered, as in this case, it can potentially inflict serious harm. Google published the details in its September 2026 Pixel security bulletin.
Google has not disclosed the vulnerability’s full particulars. However, the account circulating within the security community holds that attackers can exploit the flaw to break out of the modem’s sandbox isolation and escalate privileges, thereby gaining access to various kinds of data on the Pixel.
An Attack Requiring No User Interaction
Pixel devices remain highly secure. Google is even willing to pay a bug bounty exceeding $200,000 for a zero-click vulnerability, so an attack of this kind, in which the assailant wields a zero-click exploit, is exceedingly rare on the Pixel.
A zero-click attack refers to one in which the attacker requires no interaction from the user whatsoever, such as downloading software, clicking a link, or performing some action. In other words, the attacker need only know certain characteristics of the target (for instance, a particular installed app or a phone number) to launch the assault. In the earlier iMessage zero-click incident, attackers needed only to know the target user’s phone number or iCloud account and send a specific message to implant a backdoor program on the target’s iPhone.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.