Fri, 18 Sep

Google Patches Dangerous Pixel Modem Flaw Exploited in Zero-Click Attacks

Max Ivanov · 18.09.2026 16:15 · 3 min read

Google has released an emergency September security update for Pixel smartphones that fixes a critical vulnerability in the cellular modem firmware. The flaw, tracked as CVE-2026-58704, allowed attackers to gain elevated privileges in the system without any action by the phone’s owner. According to the company’s official data, the vulnerability has already been exploited in limited, targeted attacks.

What zero-click means and why it’s dangerous

The vulnerability is classified as zero-click because infecting a device requires no action from the user: no opening phishing links, downloading files or launching malicious apps. The compromise happens at the level of the phone’s interaction with the cellular network.

According to the official Android security bulletin, the technical issue was a logic error in permission checks in the Cellular Modem component. NIST experts gave the vulnerability a high severity rating of 8.8 out of 10 on the CVSS scale.

Importantly, the attack requires the attacker to be within network range or to use special radio equipment to interact with the victim’s device (the proximal/adjacent vector). That means there was no mass remote compromise of all Pixels over the regular internet: hackers had to be physically relatively close to their targets.

What users were actually facing

Viral posts online attribute to the vulnerability the ability to instantly gain “full control over user data.” In Google’s advisory, the wording is far more measured: the company confirms privilege escalation at the modem level but does not say whether attackers managed to escape the secure environment of the communications chip into the main Android system and read personal files.

Google described the nature of the attacks as “limited, targeted exploitation.” This indicates the flaw was used against a small number of specific individuals rather than as part of a global campaign against all Pixel owners.

How to protect your phone

The security fix is included in the September patch package with build level “2026-09-05” or later. Google strongly recommends that owners of all supported Pixel models check for updates:

  1. Go to Settings;
  2. Select System;
  3. Tap System Update and install any available updates.

Although the September bulletin fixes more than a hundred different issues, the modem vulnerability is flagged as the top priority because it has been exploited in the wild. Users are advised not to delay installing the patch to rule out any risks related to the compromise of their phone’s communications node.

Enjoy VseZavislo?

Add us to your preferred Google sources to see our news more often.

Add us to your Google

Share

Leave a comment