---
title: "Google releases September Pixel patch with a two-week delay: 110 fixes and an actively exploited modem vulnerability"
description: "Google released the September patch for 21 Pixel smartphones with a two-week delay, closing 110 vulnerabilities, including the actively exploited modem bug CVE-2026-58704. The Pixel 11 flagship did not receive the update."
date: 2026-09-16T10:16:00.000Z
lang: en
url: https://xab.info/en/posts/google-pixel-september-security-patch-en
tags: [google-pixel, android-17, security-patch, cve-2026-58704, smartphone]
publisher: "XAB.info"
---

# Google releases September Pixel patch with a two-week delay: 110 fixes and an actively exploited modem vulnerability

![Google Pixel smartphone with the Google logo on the back panel — device that received the delayed September security patch with 110 fixes](https://xab.info/media/2026/09/16/google-pixel-sentyabrskiy-patch-bezopasnosti/google-pixel-sentyabrskiy-patch-bezopasnosti-1.webp)

## 🎯 Key Points

- Google released the September patch CP3A.260905.009 with a two-week delay, containing 110 fixes, of which 46 are critical.
- Active exploitation of the modem vulnerability CVE-2026-58704, which allows privilege escalation, has been confirmed.
- The release covers 21 devices from Pixel 6 to Pixel 10a, Pixel Fold, and Pixel Tablet, but the Pixel 11 flagship did not receive the update.
- For Pixel 6 and Pixel 6 Pro, this is the last major update before support expires in October 2026.

Google released the September security update for Pixel smartphones with a two-week delay. The patch, numbered CP3A.260905.009, closes 110 vulnerabilities, of which 46 are classified as critical, and another 9 eliminate the possibility of remote code execution in modems, bootloaders, and telephony components. Alongside the security update, devices received the stable version of the Android 17 QPR1 operating system and the corresponding set of new Pixel Drop features. According to the company's assessment, installing the patch guarantees a level of protection corresponding to the period starting September 5, 2026.

### Scale of fixes and active exploitation

The main reason for urgently installing the update is that at least one of the fixed bugs is already being actively exploited: hackers are using it to carry out targeted attacks. Google confirmed the fact of limited attacks using this bug, but, as is customary, the company does not disclose the details of the internal report. It is precisely the combination of a large number of critical fixes and confirmed exploitation that makes the September patch one of the most important releases this year for Pixel device owners.

### Critical modem vulnerability CVE-2026-58704

Among the closed bugs, a special place is occupied by the modem vulnerability labeled CVE-2026-58704, which allows attackers to escalate privileges in the system. Privilege escalation at the modem level is a particularly dangerous scenario, because the base station and radio-frequency traffic are outside the user's direct control, and infection can occur remotely. Google has already confirmed that this bug is being exploited in real-world attacks, which raises the priority of the update for all supported models.

### Status of the Pixel 11 flagship

The global release covers 21 devices — from the Pixel 6 series to the Pixel 10a, as well as the foldable Pixel Fold and the Pixel Tablet. However, the new Pixel 11 flagship found itself in an unusual situation: according to Google's own assessment, the current level of security is insufficient for full protection against the modem attack. The company has not yet commented on whether this threat poses a risk to Pixel 11 owners or when the device will move to Android 17 QPR1. In effect, the flagship was left outside the main release, which looks unusual for a top-tier device.

### Contradictory data

Here the versions of the parties diverge. According to the main release description, the Pixel 11 did not receive the update: Google explicitly states that the patch level is insufficient for it, and does not name a timeline for moving to Android 17 QPR1. At the same time, a number of publications characterize the situation as an "unexpected Pixel 11 update that pushes new features to later," which can be interpreted as the flagship receiving a partial or interim release. There is no official clarification from Google on this discrepancy, so the exact support status of the Pixel 11 within the September patch remains not entirely clear and requires clarification.

### End of support for Pixel 6 and recommendations for users

For the Pixel 6 and Pixel 6 Pro smartphones, this quarterly update became the last major release: the 2021 models are approaching the expiration of their five-year guaranteed support period, which ends in October 2026. Owners of these gadgets are advised to install the current patch and consider purchasing a new smartphone. You can check for updates in the "Settings — System and software updates" menu.

## 🔍 Fact-Check Verification

- [Pixel 11 under threat: Google released a critical patch but ignored the flagship](https://www.rbc.ua/ukr/news/pixel-11-pid-zagrozoyu-google-vipustila-kritichniy-1789549835.html) - Подтверждает выпуск критического патча и то, что флагман Pixel 11 остался без полноценного обновления.
- [Google's unexpected Pixel 11 update pushes new features to later](https://itc.ua/news/neozhydannoe-obnovlenye-pixel-11-ot-google-otkladyvaet-novye-funktsyy-na-potom/) - Заголовок допускает трактовку о частичном/промежуточном обновлении Pixel 11, что расходится с основным текстом о неполучении релиза.
- [How to check Android security updates and your phone's support period](https://www.securitylab.ru/blog/personal/paragraph/362481.php) - Контекстный источник по проверке патчей и срокам поддержки; согласуется с рекомендацией для Pixel 6.
- [Google released a patch for Pixel smartphones fixing system errors](https://www.ixbt.com/live/mobile/google-vypustila-patch-dlya-smartfonov-pixel-s-ispravleniem-sistemnyh-oshibok.html) - Подтверждает факт выпуска патча для линейки Pixel с исправлением системных ошибок.

## ❓ FAQ

### Q: How many vulnerabilities does the September Pixel patch close?
**A:** The CP3A.260905.009 update contains 110 fixes: 46 critical and 9 that close remote code execution in modems, bootloaders, and telephony components.

### Q: Why does the update need to be installed urgently?
**A:** Because at least one fixed bug is already being actively used by hackers for targeted attacks; Google confirmed limited attacks through the modem vulnerability CVE-2026-58704.

### Q: Did the Pixel 11 flagship receive this update?
**A:** No, according to Google the current level of security is insufficient for the Pixel 11, and the company has not named a timeline for the device to move to Android 17 QPR1. The release covers 21 devices from Pixel 6 to Pixel 10a, Pixel Fold, and Pixel Tablet.

### Q: What should owners of Pixel 6 and Pixel 6 Pro do?
**A:** Install the current patch and consider purchasing a new smartphone, since the five-year support period for these models expires in October 2026.

### Q: Where can I check for the update?
**A:** In the "Settings — System and software updates" menu.