{"id":378104,"date":"2026-09-16T08:52:00","date_gmt":"2026-09-16T15:52:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=378104"},"modified":"2026-09-16T08:52:07","modified_gmt":"2026-09-16T15:52:07","slug":"google-patches-pixel-zero-click-flaw-exploited-in-targeted-attacks","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/google-patches-pixel-zero-click-flaw-exploited-in-targeted-attacks\/","title":{"rendered":"Google patches Pixel zero-click flaw: exploited in targeted attacks"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Google has pushed its <strong>September 2026<\/strong> security update to Pixel phones. Included in it is a fix for CVE-2026-58704, a previously unknown zero-day in the modem that, according to Google, was used in &#8220;limited, targeted&#8221; attacks before a patch was ready.<\/p>\n\n<p class=\"wp-block-paragraph\">The flaw was in the Pixel modem. Google says a successful exploit could let an attacker <strong>break out of the modem sandbox<\/strong> and reach more sensitive parts of the device. That&#8217;s a bad place for a bug to sit. Modem vulnerabilities live close to the phone&#8217;s communications stack, so they can put calls, messages, location data, and other stored information at risk.<\/p>\n\n<p class=\"wp-block-paragraph\">Google fixed CVE-2026-58704 along with <strong>109 other vulnerabilities<\/strong> in the same update. What makes this one especially serious is that the disclosure describes it as zero-click, meaning an attack could work without you tapping a link, downloading a file, or doing anything at all.<\/p>\n\n<p class=\"wp-block-paragraph\">Google hasn&#8217;t shared technical details, listed the affected Pixel models, identified the attackers, or said who was targeted. That&#8217;s typical when an exploit has already been used in the wild. The disclosure also comes after earlier Pixel zero-days in <strong>June 2024<\/strong> and April 2024 that researchers tied to forensic data extraction.<\/p>\n\n<p class=\"wp-block-paragraph\">If you use a Google Pixel regularly, install this update <strong>soon<\/strong>. Zero-click, spyware-style bugs are still a real threat, even if Pixel phones remain some of the safer <a href=\"https:\/\/android-sdk.en.softonic.com\/\" rel=\"noopener\">Android<\/a> options because Google ships patches quickly and promises at least five years of security updates.<\/p>\n\n<p class=\"wp-block-paragraph\">You can download the update now from the <strong>system update<\/strong> section in your Pixel phone&#8217;s settings.<\/p>","protected":false},"excerpt":{"rendered":"<p>Google has pushed its September 2026 security update to Pixel phones. Included in it is a fix for CVE-2026-58704, a previously unknown zero-day in the modem that, according to Google, was used in &#8220;limited, targeted&#8221; attacks before a patch was ready. The flaw was in the Pixel modem. Google says a successful exploit could let &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/google-patches-pixel-zero-click-flaw-exploited-in-targeted-attacks\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Google patches Pixel zero-click flaw: exploited in targeted attacks&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9349,"featured_media":378103,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-378104","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378104","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9349"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=378104"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378104\/revisions"}],"predecessor-version":[{"id":378105,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378104\/revisions\/378105"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/378103"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=378104"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=378104"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=378104"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=378104"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=378104"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=378104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}