Google’s September 2026 Pixel Update Bulletin contains patches beyond what’s in that month’s regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.

None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.

And at this rate, these won’t reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.

The project is characterizing this as Google “gatekeeping security patches to the standard Android platform code from Android OEMs.” The complaints

GrapheneOS says Android 17 QPR1 shipped new developer APIs that never made it into AOSP. This is something they claim hasn’t happened since Android’s Honeycomb days.

Google’s API diff report backs this up. Comparing Android 17 to QPR1 shows one new package, android.hardware.hid, plus changes across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view.

GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn’t have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.

On top of all that, there’s a compliance issue that seems to be recurring.

Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (CD1A.260905.001.A1) on September 1, and access only came through more than two weeks later.

Why this is worrying

None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code—each is the kind of thing that could pass as a one-off.

Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking GPL compliance it’s required to meet.

Don’t even get me started on what they are doing to the Android app ecosystem.

Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.

Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (classic scare tactics, btw).

GrapheneOS is one of dozens of organizations that signed onto the Keep Android Open campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.

If you ask me, this Big Tech company is doing what’s regrettably natural for it, clamping down open access to things so that its competition cannot benefit.

  • LeftReddit2@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    14 hours ago

    How do we get the average person to care about this? Like okay, as dumb as I am with tech, I probably am more techy than the average layman.

    And guess what, they do NOT care about this shit. Most of my non-tech friends still think GrapheneOS is a thing criminals or paranoid schizophrenics use.

    They also tend to not care about age verification things. “So what, you show ID at the bar or store to get alcohol, what do I care?”

    Like really gamers, how can we make the common person care about this at all? How can we communicate to them it matters and will impact them?

    • DeadEndLink@lemmy.ca
      link
      fedilink
      arrow-up
      1
      ·
      13 hours ago

      I’m picturing the GrapheneOS branded sliding scale spectrum of criminal to paranoid schizophrenic, built into my personal device features.

    • wry@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      12 hours ago

      I keep trying to tell people that Graphene is a dead end. There are other options we should be pursuing.

  • Crozekiel@lemmy.zip
    link
    fedilink
    English
    arrow-up
    4
    ·
    18 hours ago

    This has always been a thought in the back of my head regarding GrapheneOS and why I never bought into the fan hype around it. Google has always been 100% in control of the door letting these AOSP projects function and they have been slowly closing the door for ages now. It will be fully closed at some point.

  • suvtropics@lemmy.world
    link
    fedilink
    arrow-up
    24
    ·
    1 day ago

    We’re headed a dark direction. One reason I find little interest in android, smartphones, pc building, gaming hobby despite being a tech enthusiast.

    • boa@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      One can buy low powered devices rp, esp32 low budget pc laptop to play and setting up home servers.

  • Matt@lemmy.ml
    link
    fedilink
    arrow-up
    29
    ·
    edit-2
    13 hours ago

    Honestly we really need a phone with a proper Linux distro that does have same hardening as Graphene and also underclocks the modem and the rest when idle.

    • TrollAccount69@lemmy.ml
      link
      fedilink
      arrow-up
      1
      arrow-down
      7
      ·
      23 hours ago

      I honestly see it the opposite way. Graphene is doing their level best to turn Android into iOS with none of the benefits.

      They’re doing all the stuff apple did for hardware except they can’t make their own so they’re chasing stuff with the security features of iphones, they’re rewriting the system apps to take advantage of those features (like apple did) but they don’t have the benefit of a cloud data system or oversight of their app marketplace.

      I use graphene and ios daily. It’s really interesting how they’re going about all this.

  • ZkhqrD5o@lemmy.world
    link
    fedilink
    arrow-up
    222
    arrow-down
    6
    ·
    2 days ago

    It’s called installing apps, not “sideloading”. Installing your programmes into a device you own is normal, being blocked from doing that is abnormal.

  • stinkytofuisgood@lemmy.ca
    link
    fedilink
    arrow-up
    28
    arrow-down
    1
    ·
    2 days ago

    When Sony announced the end of physical disks, a low level exploit for the PS5 was released - to me the timing of this makes the message clear.

    I hope we soon have some sort of similar response with Google, whatever that may be.

    We are reaching a point where it’s evident we need to really start seriously developing open source alternatives for the technology in our life that is essentially gated by duopolies, monopolies, and oligopolies…

    Thanks to the auther for publishing important news like this. Spreading the word is so important. Making it understandable to the average person equally so. We need to educate the youth in particular before they become irreversibly entrenched in an even worse tech corpo-dystopia.

    Also, if any Grapheneos devs are reading this, I love you guys and I respect the hell outta the work you’re putting in. Anyone who has the means and the passion, I’m sure they wouldn’t mind a donation or even just feedback and engagement.

  • 4am@lemmy.zip
    link
    fedilink
    arrow-up
    86
    ·
    2 days ago

    This was already the inevitability of Android; Google was just willing to spend 15-20 years to achieve as much market dominance as possible. They fought off Palm webOS, Windows Mobile, Linux phones are just now materializing, iOS is huge but having one major competitor isn’t a problem. Now that “the reality of the world means more security is needed” Google will work their way out of any openness they once had. Perhaps even someday their own hardware will be the only game in town. They’re already by FAR the worst company when it comes to harvesting data and profiling you.

  • grue@lemmy.world
    link
    fedilink
    arrow-up
    64
    ·
    2 days ago

    Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.

    When is some country’s government finally going to grow a pair and block this shit on the grounds of antitrust law?

    • dropdrip@lemmy.ml
      link
      fedilink
      arrow-up
      13
      ·
      2 days ago

      Most governments are fascists. They want what Google is working towards: a certified device. Once you have a platform that the majority owns and is certified you can start rolling out more fascist policies, like identity verification for asinine things. The American courts failed a long time ago in regards to software with Microsoft. You could make cases against Google decades ago, but literally no one cares for some reason.

      • qonqe@lemmy.zip
        link
        fedilink
        arrow-up
        4
        ·
        1 day ago

        Spain??? Absolutely not. In fact, the new EU “Digital ID App” is going to require having a “Google or Apple verified device” for it to work. They are all in favour of restricting the internet behind IDs. Spanish President openly talked about abolishing anonymity to “protect us”. And the opposition is even worse.

        • 0x0@lemmy.zip
          link
          fedilink
          arrow-up
          2
          ·
          23 hours ago

          The EU digital act is not Spain’s digital act. Regardless, being pro-Palestine and anti-NATO doesn’t necessarily make Sanchez tech-savy.

  • story@lemmy.zip
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    1 day ago

    I’m team graphene despite having returned to the cathedral. they need thousands of dollars of our money to free up their time for the things they prioritize: this is very much a theo de raadt situation. the phone landscape is imperfect, we must take what we can get, whatever is maximum security and maintains the free software principles, projects like Android ports of self-hosted clients must continue to poison the Google narrative. it is the job of the less-skilled to serve as patron for the people who hold up the internet

  • DutchJ@lemmy.zip
    link
    fedilink
    arrow-up
    77
    ·
    edit-2
    2 days ago

    Honestly, I am running GrapheneOS (o7 to the devs, btw) until my Pixel 6a dies, and then I am switching to Jolla + SailfishOS. There is nothing more maddening to me than seeing Microslop and Google slowly filling their ecosystem with irremovable invasive bloatware and basically blocking a free market.

    • Default Username@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      32
      ·
      2 days ago

      If you don’t already have the Jolla hardware, I’d consider getting a Fairphone 6 or 6+ instead and using TheMightyCat’s build of postmarketOS. They’ve been doing some insane work with hardware enablement on the close-to-mainline kernel for that phone to the point where it’s almost 100% fully functional.

      • sudoer777@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        Does it work with other distros also? My phone is about to lose GrapheneOS support and hope to replace it with a Linux phone one day

        • Default Username@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          1 day ago

          The Fairphone 6 and 6+ can theoretically work with any distro that has 64 bit ARM support. The close-to-mainline kernel fork is where most of the important work is being done, and the rest is in portable open source software (like VoLTE support in userspace, for example).

          • sudoer777@lemmy.ml
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 day ago

            Sick I’ll check back in a few months when the GrapaheneOS phone releases and see if I should get that instead (kind of depressed about the state of Linux ARM laptops tho, Asahi Linux was great but the hardware is EOL now)

            • Default Username@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              edit-2
              14 hours ago

              When it comes to laptops, I’m personally sticking with x86 until there are faster RISC-V CPUs available that I can daily drive in a laptop.

              Even though ARM has much better battery life compared to x86, I’d still just be trading one proprietary architecture for another.

              • sudoer777@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                14 hours ago

                The current ARM chips at least don’t seem to have stuff like Intel ME, the integrated GPUs are much better as well especially for running AI models. Power efficiency as well, Intel at least is getting close but still behind. Also memory tagging. The Intel/AMD duopoly is getting old.

                • Default Username@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  13 hours ago

                  When it comes to an ME/PSP analog, there is ARM TrustZone, but each vendor has their own implementation, so whether or not it constantly runs in the background, has full access to system memory, and is completely proprietary is up to each vendor. When it comes to phones and laptops that support cellular connections on the other hand, the integrated baseband, which also has full access to system RAM and is proprietary would be my main concern.

                  RISC-V has a memory tagging implementation: https://github.com/riscv/riscv-memory-tagging/tree/main

                  Both AMD and Intel are working together on an x86 memory tagging implementation called ChkTag: https://community.intel.com/t5/Blogs/Tech-Innovation/open-intel/ChkTag-x86-Memory-Safety/post/1721490

                  AMD iGPUs are hard to beat for things like gaming. IDK much about running AI models, since I don’t care much about that kind of stuff.

                  Power efficiency is really the only thing that ARM has over x86. Also RISC-V theoretically has better power efficiency compared to ARM, though since RISC-V is so new, more advanced implementations would need to be developed first in order to match the performance per watt in a full-fledged desktop-class CPU.

    • eleitl@lemmy.zip
      link
      fedilink
      arrow-up
      14
      ·
      2 days ago

      We’ll see what Motorola will cook up. Of course GOS team can’t maintain an Android fork on their own. It doesn’t need new features, just stability and security on the right hardware platform. And it’s too bad Google killed the Pixel tablets. There isn’t anything new supported on LineageOS either. Seems I have to bite the bullet, and look at Linux tablets.

      • 0x0@lemmy.zip
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        Of course GOS team can’t maintain an Android fork on their own.

        Isn’t that what they’ve been doing?

        • eleitl@lemmy.zip
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          It would be hard fork vs a soft fork. A lot more work. But in principle a project that doesn’t need features but stability is viable. See *BSD.

    • JustEnoughDucks@slrpnk.net
      link
      fedilink
      arrow-up
      11
      arrow-down
      2
      ·
      2 days ago

      Sadly, security on the Jolla is laughable. Comparable to a standard Linux installation years ago, from what I have heard…

      It is so dumb that pretty much we only have to make these giant compromises because of greed.