Google has said that a bug in its Pixel smartphones' software was exploited in limited and targeted cyberattacks. The company said on Tuesday that the bug, tracked as CVE-2026-58704, has now been patched.
According to the limited details released about the vulnerability, the bug was found in the Pixel phones' modem, which lets the device connect to the internet. Exploiting it could allow an attacker to gain access beyond the sandboxed walls of the modem and into the broader phone's data, a vulnerability known as privilege escalation.
The bug can be exploited silently and without any interaction from the phone owner in what is known as a zero-click attack, meaning a victim does not need to click on a link or open a file.
Google did not say who was exploiting the bug, and a spokesperson for Google did not return a request for comment. It is not uncommon for bugs like this one to be abused by surveillance vendors, such as spyware makers, who sell access to their data-stealing software to governments and law enforcement agencies.