Targeted attacks exploit a Pixel modem weakness without user action

Targeted attacks exploit a Pixel modem weakness without user action. Supported Pixel phones face a high-severity cellular modem weakness that has been used in limited, targeted attacks.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.

Supported Pixel phones face a high-severity cellular modem weakness that has been used in limited, targeted attacks. Google says the issue can allow an attacker to escalate privileges through a permission bypass without requiring user interaction. The available reporting describes an adjacent-network attack path rather than broad exploitation from anywhere on the internet. CISA added the weakness to its Known Exploited Vulnerabilities catalog on September 16th.

The modem is a security-sensitive component that operates below many familiar mobile application controls. That can make a modem weakness useful as part of a multi-step intrusion. Google hasn’t identified who conducted the attacks, who was targeted or what the operation was intended to achieve.

Leaders managing mobile fleets should verify patch levels centrally rather than relying on users to confirm that updates were installed. Defenders should prioritize high-risk users and devices used for sensitive communications. The larger lesson is that mobile hardware components need a place in enterprise vulnerability management. Update supported Pixel devices to the September 5th, 2026 security patch level or later and verify compliance centrally.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Targeted attacks exploit a Pixel modem weakness without user action
Broadcast by