Google says some Pixel phone owners were hacked in zero-day attacks
Google confirmed that a zero-day vulnerability in its Pixel smartphone software was actively exploited in limited, targeted cyberattacks before a security fix was deployed. The critical flaw, tracked as CVE-2026-58704, was identified within the device modem component responsible for managing internet and cellular connectivity. According to security disclosures, the flaw enabled threat actors to execute zero-click privilege escalation attacks. This allowed attackers to breach sandbox boundaries within the modem and access sensitive data stored across the broader device without requiring any interaction or link clicks from the device owner. Google stated that the vulnerability showed indications of targeted exploitation, a pattern frequently associated with commercial spyware vendors and state-aligned cyber operations. Google has officially issued a security patch addressing the vulnerability across affected Pixel models. While the breach appears limited in scope, disclosures of hardware-level zero-day vulnerabilities present mild reputational headwinds for Alphabet's hardware division and highlight ongoing cybersecurity challenges in mobile device security.