news.mlab.sh
Back to the feed
vulnerability

Pixel Modem Zero-Day Exploited in Targeted Attacks

HighCVSS 8.0
Summary

Google has patched a critical zero-day vulnerability in the Pixel phone's modem, which was being exploited in targeted attacks. The flaw allows for remote privilege escalation without user interaction, and Google suspects state-sponsored actors or commercial spyware vendors are behind the exploitation. Numerous other vulnerabilities within the Pixel devices have also been addressed in the latest update.

Google announced on Tuesday that it had addressed a critical zero-day vulnerability within the Pixel phone's modem. The vulnerability, identified as CVE-2026-58704, allows for remote privilege escalation without requiring any user interaction. According to the CVE record, a logic error within the modem’s code enables an attacker to bypass permission checks, granting them elevated access to the device. Google states it is aware of ‘limited, targeted exploitation’ of this vulnerability.

Beyond the zero-day, the latest Pixel updates include a substantial number of other security patches addressing over 100 vulnerabilities specific to Pixel devices. Many of these vulnerabilities are classified as critical, potentially enabling remote code execution or privilege escalation. These critical flaws impact components such as the multimedia subsystem, VPU, modem, telephone, bootloader, TEE, libpixelimsmedia, GDMC, GSA, and GPCA.

While Google has not yet attributed the exploitation to a specific threat actor, the nature of the zero-day – its remote and targeted nature – is characteristic of attacks previously linked to commercial spyware vendors and state-sponsored actors. The update also includes fixes for a broader range of vulnerabilities, highlighting the ongoing efforts to secure the Pixel ecosystem.

Read the full article at SecurityWeek