A logic error in Pixel modems lets attackers climb in silently

A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.

CSBadmin
2 Min Read

Pixel handsets are carrying an exploitable hole below Android, and Google has already shipped the repair in its September 2026 update.

Tracked as CVE-2026-58704, the flaw scores 8.0. NVD traces it to a broken permission check inside the modem code. An attacker within radio range can elevate privileges remotely, needing no execution privileges of their own and no action from the phone’s owner.

Put plainly, it is a zero-click bug: nothing to tap, nothing to open, nothing to notice.

Google has offered no detail on the intrusions beyond describing “limited, targeted exploitation,” and has not named an actor.

The update carries 109 other Pixel fixes. Of those, 88 allow privilege escalation, ten leak information, nine permit remote code execution and two enable denial of service. Two high-severity elevation bugs sit in kernel components, and 46 critical flaws span Pixel parts including BigOcean, the bootloader, the IP Multimedia Subsystem and the Trusted Execution Environment.

The three-day federal patch clock started September 16, when CISA added the bug to its Known Exploited Vulnerabilities catalog. Civilian agencies have until September 19.

Patch level 2026-09-05 or later clears the whole set; owners reach it through Settings, then Security and privacy.

One structural point is worth remembering. Modem and baseband code runs beneath the operating system, usually out of reach for mobile threat defense agents, and it is reachable over the air.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.