Urgent.News

What's breaking now, across thousands of outlets.

Tech

Google rolling out Android 17 QPR2 Beta 5 for Pixel

Android 17 QPR2 Beta 5 now available for Pixel devices, with this release nearly three weeks since the last update. more…

Google rolling out Android 17 QPR2 Beta 5 for Pixel

Google Pixel smartphones have been compromised in zero-click attacks, according to recent warnings from both Google and U.S. cybersecurity authorities. The exploit stems from a zero-day improper authorization bug present in the cellular modems of Pixel devices, enabling attackers to bypass permission checks and elevate privileges without any user involvement. This vulnerability, identified as CVE-2026-58704, was disclosed by Google on Tuesday and is already under targeted exploitation by malicious actors.

Details surrounding the extent of the exploitation and the specific actions taken by attackers remain sparse. However, it is known that these zero-click attacks are commonly employed by commercial spyware developers to monitor targeted individuals. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included the CVE in its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch the flaw within three days, until September 19.

On a related note, CISA also added two Google Chromium vulnerabilities, CVE-2026-85046 and CVE-2026-87491, to its KEV catalog earlier this month. These vulnerabilities, which affect Chromium-based browsers such as Google Chrome, Microsoft Edge, and Opera, allow remote attackers to execute code within the sandbox via specially crafted HTML pages or cause an out-of-bounds write, respectively.

Security researchers have warned that espionage groups, possibly linked to China, have combined three bugs, including CVE-2026-85046, to infiltrate networks belonging to organizations in the U.S. and Southeast Asia.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at 9to5google.com →

More in Tech

Github Actions: Re-intentar automáticamente los jobs de CI que un reclamo de spot instance mató

Mi CI corre en un runner spot ARM64 autoalojado. Cuando AWS se lleva la instancia de vuelta a media corrida, GitHub muestra una X roja en cualquier paso que estuviera corriendo, y se ve idéntico a una…

  • GitHub Actions can automatically retry CI jobs killed by spot instance reclaim.
  • Listener triggers after CI or deployment run finishes to identify failed runs.
  • Three cases prevent automatic retry: recent run, concurrency group issue, or shutdown signal.

More from Wednesday 16 September →