Some Pixel phone owners had their devices compromised, Google says, after a modem software flaw allowed silent, targeted intrusions that could reach data beyond the modem. The company reported that the vulnerability, tracked as CVE-2026-58704, has been patched.

Google described the flaw as residing in the phone modem, the component that handles network connections. Exploitation could let an attacker escape the modem's sandbox and elevate privileges into the broader phone environment, opening access to data normally protected from the modem's processes. The company characterised the exploitation as limited and targeted rather than widespread.

The attack vector was a zero-click exploit, meaning a device could be compromised without any action by the owner, such as clicking a link or opening a file. That ability to intrude silently makes detection and user-level mitigation difficult until a vendor patch is applied.

Google did not identify who carried out the attacks. A company spokesperson did not respond to a request for comment. The company’s disclosure stops short of naming an attribution, leaving details about the attackers and their motivations unspecified.

Security observers note that flaws with these characteristics are commonly abused by commercial surveillance vendors, which sell access to data-stealing software to governments and law enforcement. Google’s advisory did not link the incident to any specific vendor, but the profile of the vulnerability aligns with previously observed spyware tradecraft.

For now the immediate change is technical: Google says it has issued a patch for CVE-2026-58704. Affected devices will need that update installed to close the pathway the company described. Beyond the patch, the episode underscores the risk posed by modem-level vulnerabilities that can bypass internal isolation and reach sensitive phone data. The security community and device owners will be watching for any follow-up disclosure from Google and for signs that the flaw is being reused by other actors.