Google Pixel phones pwned in zero-click attacks
CISA gives federal agencies just 3 days to patch
Google Pixel smartphones have been compromised in zero-click attacks, according to recent warnings from both Google and U.S. cybersecurity authorities. The exploit stems from a zero-day improper authorization bug present in the cellular modems of Pixel devices, enabling attackers to bypass permission checks and elevate privileges without any user involvement. This vulnerability, identified as CVE-2026-58704, was disclosed by Google on Tuesday and is already under targeted exploitation by malicious actors.
Details surrounding the extent of the exploitation and the specific actions taken by attackers remain sparse. However, it is known that these zero-click attacks are commonly employed by commercial spyware developers to monitor targeted individuals. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included the CVE in its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch the flaw within three days, until September 19.
On a related note, CISA also added two Google Chromium vulnerabilities, CVE-2026-85046 and CVE-2026-87491, to its KEV catalog earlier this month. These vulnerabilities, which affect Chromium-based browsers such as Google Chrome, Microsoft Edge, and Opera, allow remote attackers to execute code within the sandbox via specially crafted HTML pages or cause an out-of-bounds write, respectively.
Security researchers have warned that espionage groups, possibly linked to China, have combined three bugs, including CVE-2026-85046, to infiltrate networks belonging to organizations in the U.S. and Southeast Asia.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Google Pixel phones pwned in zero-click attacks theregister.com