Google released the September security update for Pixel smartphones with a two-week delay. The patch, numbered CP3A.260905.009, closes 110 vulnerabilities, of which 46 are classified as critical, and another 9 eliminate the possibility of remote code execution in modems, bootloaders, and telephony components. Alongside the security update, devices received the stable version of the Android 17 QPR1 operating system and the corresponding set of new Pixel Drop features. According to the company's assessment, installing the patch guarantees a level of protection corresponding to the period starting September 5, 2026.

Scale of fixes and active exploitation

The main reason for urgently installing the update is that at least one of the fixed bugs is already being actively exploited: hackers are using it to carry out targeted attacks. Google confirmed the fact of limited attacks using this bug, but, as is customary, the company does not disclose the details of the internal report. It is precisely the combination of a large number of critical fixes and confirmed exploitation that makes the September patch one of the most important releases this year for Pixel device owners.

Critical modem vulnerability CVE-2026-58704

Among the closed bugs, a special place is occupied by the modem vulnerability labeled CVE-2026-58704, which allows attackers to escalate privileges in the system. Privilege escalation at the modem level is a particularly dangerous scenario, because the base station and radio-frequency traffic are outside the user's direct control, and infection can occur remotely. Google has already confirmed that this bug is being exploited in real-world attacks, which raises the priority of the update for all supported models.

Status of the Pixel 11 flagship

The global release covers 21 devices — from the Pixel 6 series to the Pixel 10a, as well as the foldable Pixel Fold and the Pixel Tablet. However, the new Pixel 11 flagship found itself in an unusual situation: according to Google's own assessment, the current level of security is insufficient for full protection against the modem attack. The company has not yet commented on whether this threat poses a risk to Pixel 11 owners or when the device will move to Android 17 QPR1. In effect, the flagship was left outside the main release, which looks unusual for a top-tier device.

Contradictory data

Here the versions of the parties diverge. According to the main release description, the Pixel 11 did not receive the update: Google explicitly states that the patch level is insufficient for it, and does not name a timeline for moving to Android 17 QPR1. At the same time, a number of publications characterize the situation as an "unexpected Pixel 11 update that pushes new features to later," which can be interpreted as the flagship receiving a partial or interim release. There is no official clarification from Google on this discrepancy, so the exact support status of the Pixel 11 within the September patch remains not entirely clear and requires clarification.

End of support for Pixel 6 and recommendations for users

For the Pixel 6 and Pixel 6 Pro smartphones, this quarterly update became the last major release: the 2021 models are approaching the expiration of their five-year guaranteed support period, which ends in October 2026. Owners of these gadgets are advised to install the current patch and consider purchasing a new smartphone. You can check for updates in the "Settings — System and software updates" menu.