Google says that a bug in its Pixel smartphones’ software was exploited in limited and targeted cyberattacks. The company said Tuesday that the bug, tracked as CVE-2026-58704, has now been patched.
According to the limited details about the vulnerability, the bug was found in Pixel phones’ modem, which lets the device to connect to the internet. Exploiting the bug could allow an attacker to gain access beyond the sandboxed walls of the modem and into the broader phone’s data, a vulnerability known as privilege escalation.
The bug can be exploited silently and without any interaction from the phone owner in what’s known as a “zero-click” attack, meaning a victim does not need to click on a link or open a file.
Google did not say who was exploiting the bug, and a spokesperson for Google did not return a request for comment. It’s not uncommon for bugs like this one to be abused by surveillance vendors, such as spyware makers, who sell access to their data-stealing software to governments and law enforcement agencies.




