important · Mobile — Pixel
Google says a no-interaction Pixel modem privilege escalation is under targeted exploitation.
Affects
Supported Google Pixel phones running the affected cellular-modem firmware.
Hostile cellular traffic can reach the vulnerable authorization logic without credentials or user interaction and bypass permission checks in the modem context.
Detail and 3 sources
Google has published a fix, but pre-fix firmware remains accepted.
Chain to watch
Deliver attacker-controlled cellular traffic→↓Bypass modem permission checks→↓Escalate privileges in the modem context→↓An application-processor pivot or persistence has not been established.
Unverified chainObtain incident-chain evidence or a firmware diff that identifies the resulting execution context and any application-processor transition.
Public evidence does not tell us whether the observed chain crosses into the Android application processor or persists beyond the modem.