Summary of Pixel modem zero-click exploit: Google confirms targeted attacks
- Google confirmed that a critical Pixel modem vulnerability (CVE-2026-58704) was exploited in limited, targeted zero-click attacks before a patch was released.
- The exploit requires no user interaction and can be carried out by an attacker who is physically nearby, bypassing Android's security protections.
- The September 2026 security update, part of Android 17 QPR1, fixes this vulnerability along with over 200 other security issues.
- Pixel owners should immediately check for the update by going to Settings > System > Software updates > System update.
- CISA has added the flaw to its list of known exploited vulnerabilities, calling it a significant risk to federal networks.
Google confirms Pixel modem exploit used in targeted attacks
If you own a Google Pixel phone, you should check for a software update right now. Google has confirmed that a serious security flaw in the cellular modem of some Pixel devices was used in real-world attacks before the company could fix it.
The vulnerability, officially listed as CVE-2026-58704, is what security experts call a "zero-click" exploit. That means an attacker could potentially take control of sensitive parts of your phone without you ever tapping a link, opening a file, or doing anything suspicious. Google released a patch for this issue as part of the September 2026 security update, which also bundles fixes for more than 200 other vulnerabilities.
Here is what we know about the attack, which Pixel phones might be at risk, and the one step you need to take to protect yourself.
What the Pixel modem vulnerability does
What this means for Pixel modem zero-click exploit
The vulnerability was found deep inside the software that runs the cellular modem on Pixel phones. The modem is the component that connects your phone to mobile networks for calls, texts, and data. According to Google's own description, the issue is a "permission bypass due to a logic error in the code." In plain English, a hacker could trick the modem into granting access to data it should not be able to reach.
The attack could be carried out remotely, as long as the attacker was physically nearby — what Google calls "proximal/adjacent" access. No user interaction was needed. This type of exploit is especially dangerous because you cannot avoid it just by being careful online.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its list of "known exploited vulnerabilities," noting that it poses "significant risks to the federal enterprise." CISA also confirmed that the exploit was used against Pixel devices.
Who was targeted and what we still do not know
Google has not shared the exact details of how the exploit worked, which specific Pixel models were affected, or how many people were targeted. The company described the attacks as "limited and targeted." That suggests the exploit was not used in a widespread, automated campaign but was instead aimed at specific individuals or small groups.
Because the attack is zero-click and works through the modem, it could potentially be deployed without leaving obvious traces that a user would notice. That makes it a powerful tool for surveillance or data theft. Google has not said who was behind the attacks or what kind of data the attackers were after.
How to protect your Pixel phone right now
The fix is already available. Google released the Android 17 QPR1 update on September 16, 2026, which includes the patch for CVE-2026-58704 along with over 200 other security fixes. The update also brings new features like Harry Potter themes and contact VIPs, but the security patch is the most important reason to install it right away.
If you have a Pixel phone, here is how to check for the update:
- Open the Settings app on your Pixel.
- Scroll down and tap System.
- Tap Software updates.
- Tap System update.
- If an update is available, follow the on-screen instructions to download and install it.
You can also check for updates by going directly to the mobile news section on MobileBurn for the latest patch announcements. Once the update is installed, your phone will be protected against this specific exploit.
What this means for Pixel owners going forward
This incident is a reminder that even the most careful smartphone user can be vulnerable to zero-click attacks. Because the exploit does not require you to click a malicious link or download a shady app, traditional advice about avoiding suspicious content does not help here.
The best defense is to keep your phone's software up to date. Google Pixel phones receive regular monthly security patches, and this is exactly the kind of scenario those patches are designed for. If you want to learn more about how to stay safe, check out our mobile security guides for practical tips on securing your device.
For those who want to compare how different phone makers handle security updates, our phone comparison tool can help you see which manufacturers offer the longest support windows. And if you are thinking about buying a new phone and security is your top priority, our best phones guide ranks devices by their security track record.
