🚨Google Discloses Zero-Day Bug in Pixel Modems
Your Pixel phone's modem is vulnerable to zero-click attacks
TL;DR
Google disclosed a zero-day bug in Pixel phones' cellular modems, allowing attackers to bypass permission checks and escalate privileges without user interaction. CISA added the vulnerability to its KEV catalog and gave federal agencies three days to patch the flaw.
Google disclosed a zero-day bug in Pixel phones' cellular modems, allowing attackers to bypass permission checks and escalate privileges without user interaction. This vulnerability, tracked as CVE-2026-58704, poses a significant risk, especially for targeted individuals and organizations. CISA added the flaw to its Known Exploited Vulnerabilities Catalog, giving federal agencies three days to patch the issue. The bug can be exploited in zero-click attacks, a common tactic used by commercial spyware makers. Users must update their phones to fix the issue.

Key Points
CVE-2026-58704: zero-day improper authorization bug in Pixel phones' cellular modems, tracked by Google on Tuesday
CISA gave federal agencies three days to patch the flaw, until September 19
The vulnerability allows attackers to bypass permission checks and escalate privileges without user interaction
CVE-2026-85046: type confusion flaw in Chromium's V8 JavaScript engine, affecting all Chromium-based browsers
CVE-2026-87491: out-of-bounds write vulnerability allowing remote code execution in Chromium-based browsers
Why It Matters
If you're using a Google Pixel phone, your modem is vulnerable to zero-click attacks, allowing attackers to bypass permission checks and escalate privileges without user interaction. CISA's addition of the flaw to its KEV catalog highlights the severity of the issue, especially for targeted individuals and organizations. Users must update their phones to fix the issue, and federal agencies have three days to patch the flaw.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,482 builders reading daily.