Google confirmed that a critical modem vulnerability in Pixel phones was exploited in limited, targeted cyberattacks before being patched in the September 2026 Android 17 QPR1 update. The zero-click flaw could allow attackers to bypass Android security protections and access sensitive data without user interaction. Google has not disclosed which Pixel models were affected or the number of users targeted.