Google confirmed that a bug in Pixel smartphones’ modem was exploited in targeted zero‑day attacks, prompting a patch to address the vulnerability.

Google disclosed that a previously unknown flaw in the modem firmware of certain Pixel smartphones was weaponized in targeted zero‑day attacks, compromising a limited number of users before a security patch was released.

What the vulnerability entailed

The issue, tracked internally as CVE‑2026‑XXXXX, allowed attackers to execute arbitrary code through the device’s cellular modem, bypassing the Android operating system’s usual security layers.

Google’s Threat Analysis Group said the exploit was “highly sophisticated” and appeared to be part of a broader campaign aimed at extracting data from high‑value individuals.

How the attacks were carried out

Researchers observed that the malicious code was delivered via specially crafted SMS messages that triggered the modem bug when processed. The payload then opened a covert channel for remote command‑and‑control communication.

Because the vulnerability resided in the modem firmware, it could not be mitigated by standard Android app permissions, making detection difficult for end users.

Google’s response and mitigation

Google issued an emergency update for affected Pixel models, patching the modem firmware and revoking the compromised certificates used by the attackers.

The company also urged users to install the update immediately and to avoid interacting with suspicious SMS messages, especially those containing unexpected links or attachments.

  • Check for the latest security update in Settings → System → Advanced → System update
  • Delete any unsolicited SMS messages from unknown senders
  • Consider using a secondary device for high‑risk communications
"We are actively working with law‑enforcement partners to identify the actors behind this campaign," a Google spokesperson said.

Google has not disclosed the number of devices affected, but the company emphasized that the attack was limited to a small, targeted group rather than a widespread exploit.

TechCrunch coverage of Google’s Pixel zero‑day hack