Telekom vereinfacht MultiSIM auf iPhones: Nahtloser Gerätewechsel per Handoff

Pixel Smartphones: Google Patches Actively Exploited Zero-Click Modem Flaw

Google has patched a dangerous vulnerability in the modems of its Pixel smartphones, which the company says was actively exploited in targeted attacks prior to the release of a fix. Tracked as CVE-2026-58704, the vulnerability enables zero-click attacks, meaning victims do not need to open a file or click a link for malicious code to be executed on their device.

Escape from the Modem Sandbox

The issue stems from a logic error in permission verification. This allows attackers to bypass security mechanisms and escalate privileges remotely. As security analyses demonstrate, this flaw enables an escape from the isolated modem sandbox (a restricted environment for cellular processes) into the broader Android system, allowing sensitive device data to be extracted.

Security experts rate the severity of the flaw as high: while analysis services list the CVSS score (a standard for evaluating the severity of security vulnerabilities) at 8.0, the US Cybersecurity and Infrastructure Security Agency (CISA) rates it at 8.8. Google has not disclosed who is behind the targeted attacks or how many victims have been affected so far. In practice, such zero-click exploits are frequently developed and deployed by commercial spyware vendors. After Google warned of active attacks targeting the modem vulnerability in Pixel smartphones, CISA also added the flaw to its Known Exploited Vulnerabilities catalog. US federal agencies are required to apply the patch within three days, by September 19, 2026.

See also  Critical Gitea Flaw CVE-2026-60004: CISA Warns of Active Attacks as Thousands of Servers Stay Exposed

Extensive September Update Patches Hundreds of Flaws

The necessary fix is included in Android’s latest September security update. Pixel device users are protected starting with security patch level 2026-09-05. The update is being rolled out alongside the Android 17 QPR1 release and build CP3A.260905.009.

Beyond the modem flaw, the update resolves numerous other vulnerabilities: depending on how component fixes are counted, the bulletin includes anywhere from 100 to over 200 patches across areas such as the kernel, GPU, Bluetooth, NFC, and bootloader, including several critical remote code execution vulnerabilities.

Affected Models and Recommendations

The update is available for Pixel models starting from the Pixel 6 series. For the Pixel 6 and Pixel 6 Pro, this marks the final planned major update before the end of their regular support window. Regarding device coverage, reports vary slightly: while some outlets list the Pixel Fold and Pixel Tablet as recipients of the build, other sources suggest the tablet or the newer Pixel 11 series are initially excluded from this specific QPR1 rollout.

Given that the exploit is actively being used in the wild and requires no user interaction, Pixel smartphone owners should trigger the system update immediately. You can check the update status and trigger a manual download in Android settings under System > Software update.

Sources: Borncity.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top