Google has released Android 17 QPR1, an update that closes a modem security hole in Pixel smartphones. BornCity reports the flaw was a zero-click issue, meaning it could be triggered without any action from the device owner. Google has warned that the vulnerability was under active attack, according to Golem.de.
The patch arrives alongside the September 2026 Pixel Drop, which Google detailed on its own blog. That release brings new Pixel VIP features and additional functions for Pixel Watch, per blog.google. Coverage from PC-WELT and heise online also describes the drop as a substantial update for Pixel phones and watches.
The modem flaw is the most serious item in the package. Because it required no user interaction, it posed a risk to affected devices even when owners did nothing unusual. Google's warning that the bug was already being exploited, as reported by Golem.de, raises the urgency of installing the update.

BornCity's headline frames the fix as the central change in Android 17 QPR1, while the broader Pixel Drop coverage focuses on feature additions for phones and wearables. The two strands — a security patch and a feature release — shipped together in the same update cycle.
What to watch next: whether Google or other outlets publish further technical detail on the modem flaw, and whether additional Android devices beyond Pixel phones receive the same fix.
