1 of 1
Story summary
- Google disclosed a high-severity zero-day bug (CVE-2026-58704) in Pixel phones’ modems.
- The flaw lets attackers bypass permissions and execute privileged code without user interaction.
- CISA added the CVE to its KEV catalog and set a September 19 deadline for agency patches.
- Google warned the vulnerability was under limited, targeted exploitation before the fix.
- Proofpoint reported four Chinese-linked espionage groups chained three bugs, including V8 type-confusion (CVE-2026-85046) and out-of-bounds write (CVE-2026-87491).
