Google has patched a serious zero-click vulnerability in its Pixel smartphone lineup that was being exploited in limited, targeted attacks.

The flaw, tracked as CVE-2026-58704, resided in the Pixel modem — the component responsible for cellular connectivity. An attacker could exploit it remotely without any interaction from the device owner, gaining privilege escalation beyond the modem sandbox into the phone's broader data.

Google did not disclose who was behind the exploitation, but zero-click modem vulnerabilities of this kind are typically associated with commercial surveillance vendors that sell spyware to governments and law enforcement. The company said the bug "may be under limited, targeted exploitation" and has now been patched.

The disclosure comes amid a busy year for Android security. Google's September 2026 update fixed 180 vulnerabilities across the platform, including two other actively exploited zero-days (CVE-2025-38352 and CVE-2025-48543). Earlier in 2026, Google Project Zero published research on a separate zero-click exploit chain targeting the Pixel 9's Dolby audio processing stack.

Pixel users should install the latest security update immediately. The vulnerability underscores the ongoing risk in baseband firmware — a layer that operates below the operating system and is difficult for users to monitor or protect directly.