Wednesday, September 16, 2026
Tech Beat
Sep 16, 2026, 2:47 PMCybersecurity

Google Patches Pixel Zero-Day After Targeted Zero-Click Hacks

Google patched Pixel flaw CVE-2026-58704 after limited, targeted zero-click attacks silently escaped the modem sandbox and reached broader phone data.

Listen to this briefingAudio briefing

Summary

As of September 16, 2026, Google says attackers had exploited CVE-2026-58704 in limited, targeted cyberattacks against some Pixel owners. Google said Tuesday that it had patched the zero-day, which affects the phones’ modem, the component connecting devices to the internet.

The flaw enables privilege escalation beyond the modem’s sandbox into broader phone data. It can be triggered silently as a zero-click exploit, requiring no link click or file opening. Google has not identified the attackers, and its spokesperson did not respond to a request for comment. Such flaws are sometimes abused by surveillance vendors and spyware makers selling data-stealing tools to governments and law enforcement, but Google has not linked this exploitation to any vendor.

Positives

  • Google has patched CVE-2026-58704 after detecting active exploitation against Pixel owners.
  • Google characterized the observed cyberattacks as limited and targeted rather than widespread.
  • Google disclosed that the vulnerability affects Pixel modems and permits privilege escalation beyond their sandbox.

Risks & concerns

  • CVE-2026-58704 was exploited against some Pixel owners before Google patched it.
  • Zero-click exploitation requires no link click, file opening or other action from the victim.
  • Successful attacks can escape the modem sandbox and gain access to broader phone data.
  • Google has not identified the attackers or disclosed which Pixel owners were targeted.
  • Comparable flaws are sometimes abused by spyware vendors selling data-stealing capabilities to governments and law enforcement.
Primary sourceTechCrunchhttps://techcrunch.com/2026/09/16/google-says-some-pixel-phone-owners-were-hacked-in-zero-day-attacks/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 15

Worst Cyberattacks of 2026: DOGE, IDScan, Meta and Critical Infrastructure Breaches

CybersecuritySep 15

Exein Raises $270 Million at $1.7 Billion Valuation to Secure Physical AI

CybersecuritySep 14

HBO Max Reddit Ads Spread ClickFix Malware to Mac and Windows Users