Full Breakdown
Zero-Day Modem Flaw in Google Pixel Phones Exploited in Zero-Click Attacks
By Drooid · · How we work
Core Event
Google disclosed a high-severity vulnerability in the cellular modem of Pixel smartphones, tracked as CVE-2026-58704. The bug allows an attacker to bypass permission checks and elevate privileges without any user interaction, enabling “zero-click” exploitation. According to Google, the flaw was already being used in the wild before a patch was released.
Background & Context
Zero-click attacks are a common technique for commercial spyware, allowing surveillance of targeted individuals without their knowledge. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously highlighted similar threats, adding two Google Chromium flaws—CVE-2026-85046 (a type-confusion issue in the V8 JavaScript engine) and CVE-2026-87491 (an out-of-bounds write in the same engine)—to its Known Exploited Vulnerabilities (KEV) catalog. Security researchers at Proofpoint reported that at least four espionage groups, most suspected of links to China, combined three bugs, including CVE-2026-85046, to infiltrate networks in the United States and Southeast Asia.
Official Statements & Responses
CISA classified the vulnerability as a frequent attack vector for malicious actors and noted that it poses significant risks to the federal enterprise. In response, CISA added CVE-2026-58704 to its KEV catalog and gave federal agencies until September 19 to apply the required patches.
Data & Statistics
- CVE-2026-58704 – Pixel modem zero-click flaw, disclosed Tuesday.
- CVE-2026-85046 – Type-confusion bug in Chromium’s V8 engine, affects Chrome, Edge, Opera.
- CVE-2026-87491 – Out-of-bounds write in V8, also affects Chromium-based browsers.
- Four espionage groups (suspected Chinese links) linked these bugs to network intrusions in the U.S. and Southeast Asia.
- September 19 – CISA-mandated deadline for federal agencies to patch the modem flaw.
What’s Next
Google’s patch is available to Pixel owners who install the latest system update. Federal agencies must complete remediation by September 19, after which CISA may consider additional enforcement actions. Users of non-federal Pixel devices are similarly advised to update promptly to mitigate the risk of remote, zero-click compromise.
