Pixel modem zero-day patched after targeted exploitation

Google patched a high-severity zero-day in the Pixel modem after reports of limited, targeted exploitation. The flaw required no user interaction and could permit privilege escalation.

Google released a patch on Tuesday for a high-severity zero-day in the Pixel phone modem after detecting limited, targeted exploitation. The flaw is tracked as CVE-2026-58704 and can allow escalation of privileges without any user action.

The vulnerability exists in the cellular modem and is caused by a logic error that creates a permission bypass. The official CVE record states: “In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.”

Google released the fix as part of a Pixel update that bundles the latest Android security patches. The company acknowledged limited, targeted exploitation but did not identify an attacker.

The update resolves more than 100 Pixel-specific vulnerabilities. Nearly 50 were rated critical and could permit remote code execution or privilege escalation across components such as the multimedia subsystem, the visual processing unit, modem and telephony stacks, bootloader, the trusted execution environment and Pixel libraries and services.

Because the bug is in the modem stack, it can be triggered remotely by proximity to the device’s wireless interface. The bulletin did not provide technical details about the exploit, citing active exploitation and the need to protect users while patches roll out.

Pixel owners should check device settings for available updates and install them through official update channels to receive the modem fix and other security patches.

Articles by this author