Pixel Modem Zero-Day Exploited in Targeted Attacks
ID: 4974fc01-3bf5-5057-8bae-08025689fceb
STIX ID: report--4974fc01-3bf5-5057-8bae-08025689fceb
Feed Name: CosmicBytez Labs
Google released a September 15, 2026 security update addressing a zero-day in the Pixel cellular modem (CVE-2026-58704) that permits remote, zero-click permission bypass and has indications of limited, targeted exploitation; affected devices include Pixel 6–11, Pixel Tablet, and Pixel Fold, and CISA added the CVE to its Known Exploited Vulnerabilities catalog. The advisory emphasizes immediate installation of the September update (patch level 2026-09-05) as there is no workaround and notes the modem's position outside Android's normal security boundaries makes detection and post-compromise visibility difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
