Google Pixel Phones Vulnerable to Zero-Click Attacks
Google Pixel Phones Vulnerable to Zero-Click Attacks
Both Google and Uncle Sam have issued warnings that attackers have exploited a zero-day improper authorization bug in Pixel phones’ cellular modems. This vulnerability can bypass permission checks and escalate privileges without any user interaction required. The hole has since been closed, provided that users update their devices. Google disclosed the high-severity vulnerability, tracked as CVE-2026-58704, on Tuesday, cautioning that the security hole “may be under limited, targeted exploitation.” In other words, miscreants found and exploited this bug before Google could fix the issue.
We have very limited details about the vulnerability itself, other than that it exists in Pixel phones’ modems, is being exploited in the wild, and can be exploited in zero-click attacks, meaning no user interaction is required. These types of zero-click attacks are frequently used by commercial spyware makers to surveil targeted individuals. 🚨
On Wednesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities Catalog and gave federal agencies just three days—until September 19—to patch the flaw. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” according to the cyber-defense agency.
Additionally, earlier this month, CISA added two Google Chromium vulnerabilities, CVE-2026-85046 and CVE-2026-87491, to its KEV catalog. CVE-2026-85046 is a type confusion flaw in Chromium’s V8 JavaScript engine that allows remote attackers to execute code inside the sandbox via a crafted HTML page. It affects all Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. The second flaw, an out-of-bounds write vulnerability tracked as CVE-2026-87491, also exists in the V8 engine, allowing for remote code execution, and affects all Chromium-based browsers.
For more details, Read full article!