Google’s September 2026 Pixel Update Bulletin contains patches beyond what’s in that month’s regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.
None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.
And at this rate, these won’t reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.
The project is characterizing this as Google “gatekeeping security patches to the standard Android platform code from Android OEMs.” The complaints
GrapheneOS says Android 17 QPR1 shipped new developer APIs that never made it into AOSP. This is something they claim hasn’t happened since Android’s Honeycomb days.
Google’s API diff report backs this up. Comparing Android 17 to QPR1 shows one new package, android.hardware.hid, plus changes across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view.
GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn’t have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.
On top of all that, there’s a compliance issue that seems to be recurring.
Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (CD1A.260905.001.A1) on September 1, and access only came through more than two weeks later.
Why this is worrying
None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code—each is the kind of thing that could pass as a one-off.
Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking GPL compliance it’s required to meet.
Don’t even get me started on what they are doing to the Android app ecosystem.
Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.
Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (classic scare tactics, btw).
GrapheneOS is one of dozens of organizations that signed onto the Keep Android Open campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.
If you ask me, this Big Tech company is doing what’s regrettably natural for it, clamping down open access to things so that its competition cannot benefit.
How do we get the average person to care about this? Like okay, as dumb as I am with tech, I probably am more techy than the average layman.
And guess what, they do NOT care about this shit. Most of my non-tech friends still think GrapheneOS is a thing criminals or paranoid schizophrenics use.
They also tend to not care about age verification things. “So what, you show ID at the bar or store to get alcohol, what do I care?”
Like really gamers, how can we make the common person care about this at all? How can we communicate to them it matters and will impact them?
I’m picturing the GrapheneOS branded sliding scale spectrum of criminal to paranoid schizophrenic, built into my personal device features.
We really need a better OS than Android.
I keep trying to tell people that Graphene is a dead end. There are other options we should be pursuing.
This has always been a thought in the back of my head regarding GrapheneOS and why I never bought into the fan hype around it. Google has always been 100% in control of the door letting these AOSP projects function and they have been slowly closing the door for ages now. It will be fully closed at some point.
We’re headed a dark direction. One reason I find little interest in android, smartphones, pc building, gaming hobby despite being a tech enthusiast.
One can buy low powered devices rp, esp32 low budget pc laptop to play and setting up home servers.
Honestly we really need a phone with a proper Linux distro that does have same hardening as Graphene and also underclocks the modem and the rest when idle.
google doing as best as it possibly can to turn android into iOS but with none of the benefits
I honestly see it the opposite way. Graphene is doing their level best to turn Android into iOS with none of the benefits.
They’re doing all the stuff apple did for hardware except they can’t make their own so they’re chasing stuff with the security features of iphones, they’re rewriting the system apps to take advantage of those features (like apple did) but they don’t have the benefit of a cloud data system or oversight of their app marketplace.
I use graphene and ios daily. It’s really interesting how they’re going about all this.
Seems like Apple should just stop being a shitty corporation then, all our problems are solved.
Huh?
We need Proper Linux/BSD phone
PostmarketOS works pretty decently on certain hardware from my understanding. Apps are lacking, though. I think you might be able to run Android apps through something like Waydroid, but I think certain apps like bank apps don’t like that.
Yeah I mean with Posh based on kde based but with native Linux app ecosystem.
SailfishOS phone ?
Yeah, not, I’m not buying a corporate owned phone again so we can repeat this later. Fully open source should be the goal.
Lmao good luck
Proprietary crap phone?
Not to mention way too expensive as well…
Furiphone?
i mean there is AOSP
And AOSP is purposefully falling behind
How so?
Many AOSP apps are dated and Google has its own closed source Google apps.
If they’re still open-source…
It’s called installing apps, not “sideloading”. Installing your programmes into a device you own is normal, being blocked from doing that is abnormal.
When Sony announced the end of physical disks, a low level exploit for the PS5 was released - to me the timing of this makes the message clear.
I hope we soon have some sort of similar response with Google, whatever that may be.
We are reaching a point where it’s evident we need to really start seriously developing open source alternatives for the technology in our life that is essentially gated by duopolies, monopolies, and oligopolies…
Thanks to the auther for publishing important news like this. Spreading the word is so important. Making it understandable to the average person equally so. We need to educate the youth in particular before they become irreversibly entrenched in an even worse tech corpo-dystopia.
Also, if any Grapheneos devs are reading this, I love you guys and I respect the hell outta the work you’re putting in. Anyone who has the means and the passion, I’m sure they wouldn’t mind a donation or even just feedback and engagement.
This was already the inevitability of Android; Google was just willing to spend 15-20 years to achieve as much market dominance as possible. They fought off Palm webOS, Windows Mobile, Linux phones are just now materializing, iOS is huge but having one major competitor isn’t a problem. Now that “the reality of the world means more security is needed” Google will work their way out of any openness they once had. Perhaps even someday their own hardware will be the only game in town. They’re already by FAR the worst company when it comes to harvesting data and profiling you.
It’s called embrace, extend, extinguish.
Microsoft pioneered it.Agree 99%. But I would argue that Google is on par with Meta on the profiling front.
Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.
When is some country’s government finally going to grow a pair and block this shit on the grounds of antitrust law?
Most governments are fascists. They want what Google is working towards: a certified device. Once you have a platform that the majority owns and is certified you can start rolling out more fascist policies, like identity verification for asinine things. The American courts failed a long time ago in regards to software with Microsoft. You could make cases against Google decades ago, but literally no one cares for some reason.
Complacency is stupidity.
Only when they stop getting some kind of benefit from it.
Maybe Spain.
Spain??? Absolutely not. In fact, the new EU “Digital ID App” is going to require having a “Google or Apple verified device” for it to work. They are all in favour of restricting the internet behind IDs. Spanish President openly talked about abolishing anonymity to “protect us”. And the opposition is even worse.
The EU digital act is not Spain’s digital act. Regardless, being pro-Palestine and anti-NATO doesn’t necessarily make Sanchez tech-savy.
I’m team graphene despite having returned to the cathedral. they need thousands of dollars of our money to free up their time for the things they prioritize: this is very much a theo de raadt situation. the phone landscape is imperfect, we must take what we can get, whatever is maximum security and maintains the free software principles, projects like Android ports of self-hosted clients must continue to poison the Google narrative. it is the job of the less-skilled to serve as patron for the people who hold up the internet
The writing has been on the wall for years now [Article from 2018]
Honestly, I am running GrapheneOS (o7 to the devs, btw) until my Pixel 6a dies, and then I am switching to Jolla + SailfishOS. There is nothing more maddening to me than seeing Microslop and Google slowly filling their ecosystem with irremovable invasive bloatware and basically blocking a free market.
If you don’t already have the Jolla hardware, I’d consider getting a Fairphone 6 or 6+ instead and using TheMightyCat’s build of postmarketOS. They’ve been doing some insane work with hardware enablement on the close-to-mainline kernel for that phone to the point where it’s almost 100% fully functional.
Does it work with other distros also? My phone is about to lose GrapheneOS support and hope to replace it with a Linux phone one day
The Fairphone 6 and 6+ can theoretically work with any distro that has 64 bit ARM support. The close-to-mainline kernel fork is where most of the important work is being done, and the rest is in portable open source software (like VoLTE support in userspace, for example).
Sick I’ll check back in a few months when the GrapaheneOS phone releases and see if I should get that instead (kind of depressed about the state of Linux ARM laptops tho, Asahi Linux was great but the hardware is EOL now)
When it comes to laptops, I’m personally sticking with x86 until there are faster RISC-V CPUs available that I can daily drive in a laptop.
Even though ARM has much better battery life compared to x86, I’d still just be trading one proprietary architecture for another.
The current ARM chips at least don’t seem to have stuff like Intel ME, the integrated GPUs are much better as well especially for running AI models. Power efficiency as well, Intel at least is getting close but still behind. Also memory tagging. The Intel/AMD duopoly is getting old.
When it comes to an ME/PSP analog, there is ARM TrustZone, but each vendor has their own implementation, so whether or not it constantly runs in the background, has full access to system memory, and is completely proprietary is up to each vendor. When it comes to phones and laptops that support cellular connections on the other hand, the integrated baseband, which also has full access to system RAM and is proprietary would be my main concern.
RISC-V has a memory tagging implementation: https://github.com/riscv/riscv-memory-tagging/tree/main
Both AMD and Intel are working together on an x86 memory tagging implementation called ChkTag: https://community.intel.com/t5/Blogs/Tech-Innovation/open-intel/ChkTag-x86-Memory-Safety/post/1721490
AMD iGPUs are hard to beat for things like gaming. IDK much about running AI models, since I don’t care much about that kind of stuff.
Power efficiency is really the only thing that ARM has over x86. Also RISC-V theoretically has better power efficiency compared to ARM, though since RISC-V is so new, more advanced implementations would need to be developed first in order to match the performance per watt in a full-fledged desktop-class CPU.
We’ll see what Motorola will cook up. Of course GOS team can’t maintain an Android fork on their own. It doesn’t need new features, just stability and security on the right hardware platform. And it’s too bad Google killed the Pixel tablets. There isn’t anything new supported on LineageOS either. Seems I have to bite the bullet, and look at Linux tablets.
Of course GOS team can’t maintain an Android fork on their own.
Isn’t that what they’ve been doing?
It would be hard fork vs a soft fork. A lot more work. But in principle a project that doesn’t need features but stability is viable. See *BSD.
Sadly, security on the Jolla is laughable. Comparable to a standard Linux installation years ago, from what I have heard…
It is so dumb that pretty much we only have to make these giant compromises because of greed.
For me, having control over my own system outweighs this. Might be naive though. Plus, I want to support these kind of initiatives.
deleted by creator
Ramp up Motorola then.











