Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in Google's September 2026 security update, which addressed over 200 vulnerabilities total.