Google has officially confirmed that Pixel smartphones were targeted by precise cyberattacks carried out through a previously unknown vulnerability in the devices' software. According to the developers, the flaw was already being exploited by malicious actors in real-world incidents. The company did not disclose the full list of affected models and declined to comment on the individuals or groups behind the attacks; however, the technical details revealed in the security bulletin point to a systemic nature of the flaw and its high level of danger to user privacy.

Attack Without a Single Click

The key feature of the incident is its zero-click format: the vulnerability was exploited without any interaction from the device owner. The victim did not need to follow malicious links, open suspicious files, reply to messages, or download third-party content. All manipulations were performed in the background, invisible to the operating system's background processes, which makes this scenario one of the most difficult to detect and one of the most valuable for surveillance actors.

Flaw in the Modem's System Code

According to technical data from the developers, the vulnerability is located in the Pixel modem's system code — the component responsible for connecting the device to mobile and wireless networks. Exploiting the flaw allowed attackers to break out of the isolated environment, the so-called modem "sandbox," and gain access to the device's main system, including user data. Such privilege escalation turns a local failure in the network module into full compromised access to the smartphone's contents.

Who Is Behind the Attacks

Cybersecurity experts explain that complex zero-click vulnerabilities of this kind are generally not used in mass cybercrime campaigns: they are purchased and deployed by providers of commercial spyware that sell surveillance tools to government agencies and intelligence services. That is precisely why the targeted nature of the attacks and the absence of public statements about "millions of devices hacked" match the typical profile of state or quasi-state surveillance rather than a classic hacking incident.

What Pixel Owners Should Do

Experts strongly recommend that all Pixel device owners install the latest Android update containing the fix. The patch can be checked in the "Settings — System & software updates" menu. Particular attention should be paid to the Pixel 6 and Pixel 6 Pro: the current quarterly update was their last major release, as the 2021 models are approaching the end of their five-year guaranteed support period, which expires in October 2026. Owners of these devices are advised to install the current patch and consider switching to a new device with up-to-date security support.