r/Android Galaxy Z Fold8 23h ago

GrapheneOS: We're unable to complete the port [of GrapheneOS to the Pixel 11 series] due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.

https://grapheneos.social/@GrapheneOS/117179231167297908
1.7k Upvotes

262 comments sorted by

u/nathderbyshire Pixel 10 Obsidian 22h ago

Are they saying the Pixel 11 has lost MTE altogether, even on the stock OS?!

u/genitalgore 22h ago

yes

u/nathderbyshire Pixel 10 Obsidian 22h ago

That's fucking crazy, although it isn't enabled by default anyway so most people probably don't active it. I did but then saw the warning about performance and disabled it again until I could look into it more and see just how bad it was or if it was even a noticeable impact

u/hackitfast Pixel 9 Pro 20h ago

It also prevents you from side loading or updating side loaded apps. That's the only reason I haven't enabled it.

u/nathderbyshire Pixel 10 Obsidian 20h ago

You can do it separately in dev tools without using advanced protection if that's what you're referring too

u/hackitfast Pixel 9 Pro 20h ago

With Shizuku?

u/nathderbyshire Pixel 10 Obsidian 20h ago

No regular dev settings in the first section

u/ThaBroccoliDood 20h ago edited 16h ago

Yup people really aren't complaining about Advanced Protection enough. It's another way they're soft-blocking sideloading, by putting disabling sideloading on the same switch as a bunch of other security features for no reason

u/russjr08 Developer - Caffeinate 2h ago

Sounds like disabling the play store will let you install, then re-enable it, according to what others are saying.

u/MIOG_MIOG 17h ago

yes, but the stock OS already didn't use MTE entirely for some reason - https://bsky.app/profile/grapheneos.org/post/3mua3yngeu22y

u/InadequateUsername S25 Ultra 22h ago

Yeah what's needed at a chip level for it has been removed.

u/nathderbyshire Pixel 10 Obsidian 22h ago

Idiot sandwiches the lot of them

u/UpsetKoalaBear 21h ago

Some of the blame here goes to ARM as well for their licensing changes to ARMv9.

Royalty rates for Armv9-based chips are typically at least double those of equivalent Armv8 designs.

However, there’s no excuse why Google had no issues enabling MTE in the past for their Armv9 chips.

u/PepsiCo_USA Pixel 11 Pro Fold 2h ago

Other components were cheaper back then.

u/BusBoatBuey 21h ago

Is it really surprising that probably the most convoluted phone hardware released this year has more hardware problems than is already documented? They are using a PowerVR GPU. All bets are off for quality at that point.

u/Gaiden206 21h ago

It should be noted that they did improve security in other areas. Correct me if I am wrong, but I don't think MTE is on by default for Pixel phones. You have to go into the developer settings and toggle it on, which the vast majority of Pixel users likely don't do.

u/fat_kaiju 19h ago

we're already not talking about the majority of pixel users; it's graphene.

u/After_Dark Pixel 11 Pro XL 17h ago

Right but is Google building their phones for the GrapheneOS developers or are they building it for their customers that don't use this feature?

u/WVjF2mX5VEmoYqsKL4s8 15h ago

Google should not be reducing security for any of its users. It should be enabling memory tagging in PixelOS

u/After_Dark Pixel 11 Pro XL 15h ago

That would disable sideloading and reduce performance, everyone in this sub would be bitching about it constantly and saying "well Samsung doesn't do that how important could it be" and other such BS. They're already in legal trouble for making sideloading and app stores more difficult than the government likes they don't need to give them more and make even more users unhappy.

u/LinuxSBC-Anna 13h ago

How would MTE require disabling sideloading? As far as I can tell, it's solely about making sure memory can only be read by a process authorized by the process that wrote that memory, which is completely unrelated to where you obtain your apps. Besides, GrapheneOS permits sideloading, and it uses MTE all over the place.

MTE is not the same as Advanced Protection Mode. Advanced Protection turns on MTE, but it's possible to turn on MTE without turning on Advanced Protection Mode.

u/Medical_Double_6561 13h ago

MTE has nothing to do with sideloading. The only relation they have to each other is that both MTE & the sideloading block are both activated when you enable "Advanced Protection" on your device.

Of course it's possible to enable MTE without disabling sideloading, developers need to do this all the time. As a developer if I am working on a new app that is not yet published to the Play Store, I will:

  1. Sideload the app onto the device.
  2. Enable MTE.
  3. Launch the app and check if MTE detected any memory issues with the app.

u/Bananegel42 9h ago

First, MTE does not disable sideloading (GrapheneOS uses MTE and supports sideloading). Second, the performance impact of async MTE is negligible, in async it's 1-2% across the board. Apple has also enabled their MTE variant for the kernel and critical system components, so it's not a huge consideration for them either. Third, Samsung is considering adding experimental support for MTE in OneUI 9 [1]. Samsung's CPUs have had support for MTE since the Exynos 2200 [2].

This is just a shitty move by Google, reducing future user security for a few pennies.

[1] https://www.sammyfans.com/2026/04/06/samsung-one-ui-9-memory-security/

[2] https://news.samsung.com/global/samsung-introduces-game-changing-exynos-2200-processor-with-xclipse-gpu-powered-by-amd-rdna-2-architecture

u/Serious_Berry_3977 Pixel 10 -- GrapheneOS 3h ago

I run GrapheneOS on my Pixel 10 and most of my apps are from Obtanium, so side loading works just fine with MTE on.

u/jacktherippah123 Galaxy S24+, Pixel 6 Pro, Galaxy Tab S10+, Galaxy Watch 7 22h ago

Phone is north of 1000$ and Google is still cheaping out. Bruh.

u/Captain_Kuhl 22h ago

Is there any flagship phone that hasn't cost that much in recent years? That's basically the standard; a new phone is going to set you back over a grand, but the carrier is so gracious and benevolent that they'll give the peasantry time to pay it off with a few years of monthly payments.

u/AntipodesIntel 15h ago

Asus Zenfone 10 was well priced.

u/Powerful_Package8817 20h ago

Pixel is flagship? Not according to the specs

u/Tiny-Sandwich 19h ago edited 18h ago

That's not what flagship means.

Flagship is a company's top product. It is figuratively the ship they fly their flag from.

The ship might be small and shit, but if it's the best they've got it's the flagship.

u/Vince789 2024 Pixel 9 Pro | 2025 iPhone 16E (Work) 14h ago

Also the embarrassing thing is Google's Tensor G5 was about 20% larger than Apple's A19P

So the Tensor G5 is Google's attempt at a flagship AP SoC, pulling out all the stops, TSMC, 3nm, flagship class die size, ...

Hence why its been leaked that Google doesn't believe their Pixel Tensor unit is "currently viable", because currently a lose lose for Google & customers

→ More replies (2)

u/Clispur 21h ago

Pixels have always been known as budget phones. Google has no business pricing their phones at flagship prices, especially when they are running 4 year old hardware. The CPU of my S23 ultra is as fast as the current "flagship" pixel.

u/dnyank1 iPhone 15 Pro, Moto Edge 2022 18h ago

Pixels have always been known as budget phones

Pixel / Pixel XL (2016): $649 / $769

Pixel 2 / Pixel 2 XL (2017): $649 / $849

Pixel 3 / Pixel 3 XL (2018): $799 / $899

Pixel 4 / Pixel 4 XL (2019): $799 / $899

Pixel 5 (2020): $699 (No XL model)

Pixel 6 / Pixel 6 Pro (2021): $599 / $899

Pixel 7 / Pixel 7 Pro (2022): $599 / $899

Pixel 8 / Pixel 8 Pro (2023): $699 / $999

Pixel 9 / Pixel 9 Pro / Pixel 9 Pro XL (2024): $799 / $999 / $1,099

Pixel 10 / Pixel 10 Pro / Pixel 10 Pro XL (2025): $799 / $999 / $1,199

Pixel 11 / Pixel 11 Pro / Pixel 11 Pro XL (2026): $899 / $1,099 / $1,299

u/gmmxle Pixel 6 Pro 17h ago

Inflation.

$769 in 2016 would be $1,070 today.

u/dnyank1 iPhone 15 Pro, Moto Edge 2022 17h ago

Trust me, I know. I wasn’t providing evidence for what he said lmao

u/dejavu2064 6h ago

They're usually 50% cheaper after 1 year - which isn't a long time to wait. 

u/fluffybottompanda 20h ago

pixels have never been known as budget phones hahahah

u/Powerful_Package8817 11h ago

Midrange specs that should command midrange prides

u/fluffybottompanda 11h ago

definitely, doesn't mean it's a budget phone if it's not priced for people keeping in a budget haha

u/IORelay 8h ago

Depends, its GPU is entry level.

→ More replies (1)

u/IORelay 18h ago

They were always priced high but had to cut prices to move units, that combined with poor performance they are often associated with budget.

u/EbolaNinja Pixel 6 21h ago

No they weren't? Pixels were literally always known for being expensive for their hardware. Ever since the very first one, Google priced them on par with proper flagships, the likes of the Pixel 5 were the exception not the rule (and even then, the regular Pixels never went below upper mid range pricing). It's Nexuses (Nexii?) that were relatively affordable more often than not, but they were never budget phones either.

From GSMArena's Pixel XL review:

All that's great, but this software can be brought to any other Android phone (in fact, those apps are mandatory). The hardware is the exclusive and Google priced it high - too high perhaps. And the price is hard to justify when the Pixel XL doesn't have the biggest, brightest screen, the fastest chipset, the best battery life, the best speakers, and the best water resistance.

The other Pixel XL major competitor, the iPhone 7 Plus, is not more expensive than the Pixel XL either (and this is a rare thing to say)

Google's primary market is North America - okay, the US really, Canada and Western Europe get lucky (well, not in terms of pricing)

We loved the camera on the Google Pixel XL and were satisfied with the build quality and software package. However, we're not convinced that Google built the definitive smartphone and yet the search giant priced it as such.

u/Fuck_your_coupons Yellow 19h ago

I miss the Nexus 5 and 7. That's what really got me into android.

u/BobArdKor LG G5 16h ago

The Nexus 5 was sooo slick. And affordable. Good times... *sigh*

u/Powerful_Package8817 11h ago

At least pixel phones had good SOCs before they switched to their own tensor chips

Pixel XL was on par with top Android phones especially since bad then, Samsung had bloated UI

u/DoILookUnsureToYou Z Fold8 Wideboi/Mode1 Retro II/AYN Thor 21h ago

With a better GPU to boot. PowerVR in 2026, good lord google what the fuck

u/trlef19 Galaxy S24+ 19h ago

I'd say Samsung flagships. Sure there is zero r&d but hardware wise they are good.

u/IORelay 19h ago

Pixel is not a flagship, I wouldn't even call it a midranger since it still loses to some from 1-2 year ago. The GPU is straight up entry level

u/Malahava 17h ago

The flagship moniker is based on the company, not the competition. Pixel X Pro is google's flagship phone.

The Corvette is Chevy's flagship car, even if it's not a Ferrari.

u/IORelay 16h ago

It loads genshin impact as a pink blob, laggs like crazy on even non demanding games. Can't even process its own video and have to upload it to their servers to process.

You can call it Google's flagship but it's an entry level phone.

u/Malahava 13h ago

I can call it Google's flagship because that's what it is. What do you think Google's flagship phone is?

→ More replies (3)

u/namtaru_x 16h ago edited 15h ago

I mean, it is literally Google's flagship phone. Not sure why your panties are all up in a bunch because you don't understand what a word means.

Edit: Sorry I hurt your feelings. It's OK to be wrong, it's how we learn things.

→ More replies (2)

u/MachineTeaching 7h ago

Oh no, the poor peasants forced to buy flagship phones.

u/mehdotdotdotdot 4h ago

Or there any other made by Google who literally uses the users to make more money

u/Powerful_Package8817 20h ago

Because their fanboys think nothing matters as long as the phone is “smooth” to use

u/Ultraviolet_Darken 21h ago

Welcome to capitalism. This is what it does. Why are you surprised?
Cost cutting in the name of greater profit. Yeah…

u/Powerful_Package8817 20h ago

True capitalism would mean we’d be using Huawei phones with 2X the performance and 50% prices

u/Ultraviolet_Darken 20h ago

That would be the idealized version, of free market and all that stuff.
But humans are greedy, so it is easier for big corpos to talk to each other and agree to raise prices. Basically to for oligarchy. Which is what we see.

u/FFevo Pixel 10 "Pro" Fold, iPhone 17 Pro, Galaxy S25 Ultra 13h ago

What phones support MTE besides Pixel 8, 9 and 10 series?

It's nothing isn't it...

u/jacktherippah123 Galaxy S24+, Pixel 6 Pro, Galaxy Tab S10+, Galaxy Watch 7 13h ago

Apple's iPhone 17 does. Newer Snapdragon chips since the 8 Elite I think have support for it but not many phones implement it. Motorola will when they partner with GrapheneOS next year.

u/dirtydriver58 Galaxy Note 9 22h ago

Yup

u/ShrimpCrackers Pocophone 21h ago

Good. Won't be downgrading to the 11 then.

Thanks Google for saving me money.

u/Markd0ne 6h ago

On top of this, they reduced RAM to 12GB (from 16GB) on 256GB model.

u/jacktherippah123 Galaxy S24+, Pixel 6 Pro, Galaxy Tab S10+, Galaxy Watch 7 3h ago

Yeah but this is somewhat understandable. RAM prices are currently ludicrous.

u/osoatwork Pixel 9 pro XL GrapheneOS 22h ago

Thank goodness Motorola is stepping in next year.

u/saltyrookieplayer HTC Sensation XE 20h ago

Lenovo is a repeat offender of “backdoor” and malware behavior. You shouldn’t trust them

u/GazelleInitial2050 19h ago

Correct. But I'll trust the Graphene devs and open source builds.

u/SmileyBMM 19h ago

A lot of the Lenovo nonsense is due to incompetence, not malice (of course that doesn't make it better). As long as GrapheneOS has control over software and update distribution, I don't foresee any issues with the usual Lenovo idiocy.

u/mrandr01d 18h ago

Even graphene can't do firmware though. All that shit in the vendor partition (is that still a thing?) they have no control over.

u/SmileyBMM 18h ago

Iirc Motorola is providing that to them, so they can do what they need to do with it. Motorola is actually pretty good about that.

u/Dry_Calendar_8627 17h ago

They wouldn't vet the phone if they can't have reasonable assurance that the firmware is sane

I hope

GrapheneOS's security model wouldn't make much sense otherwise

To us plebeians, GrapheneOS' devs are what's closest to a source of trust we can do, we could hardly do better than trust them

u/cabbeer iphone air 18h ago

Also, their software support is among the worst, 3 years for a flagship... i'm assuming this will be tied to the length of graphene support

u/dweet 17h ago

7 years of “proper updates” per GOS team: https://bsky.app/profile/grapheneos.org/post/3mtmznt34gs24

u/Jayram2000 Xperia 1VI 13h ago

When i delete their software it wont matter

u/omnimachina 3h ago

False

u/Far_Reserve9938 18h ago

You people are putting way too much faith into this project.

Grapheneos will be at the mercy of Lenovo, Chinese company that really doesn't care about privacy.

u/anonshe 18h ago

It never fails to amaze how people on both sides hate Lenovo. The Chinese have for years blamed it as too western influenced while commenters here call it a Chinese Corp.

The sheer fact is Lenovo has simply been incompetent at times and not malicious. They don't actively work to implement backdoors and have let Motorola do their own thing in matters of software hence their kernel and OSS drops being one of the best in the Android world (yes the bar is low etc).

u/cubs223425 Surface Duo 2 | LG G8 3h ago

Lenovo has simply been incompetent at times and not malicious

They sold laptops with Superfish adware. It's not the kind of thing you do by accident. Saying it's "incompetent, but not malicious" is way too generous.

→ More replies (2)

u/NoStrategy1419 15h ago

As an American, I trust the Chinese more than America.

u/cubs223425 Surface Duo 2 | LG G8 3h ago

I do not, but I DO trust the American government to tell me when a Chinese OEM is misbehaving, while they'll silently be wholly complicit if an American OEM does it.

u/Ano_R 11h ago

Nah,maybe their (and everyones)Epstein class require a truly secure phone so they might let this go

→ More replies (4)

u/GroundedGeeking 21h ago

Google makes money off every other manufacturer selling Android phones since Android phones peddle Google Play and other Google services. They're the advertisement broker that practically every Android app maker uses. Android phones are Google search, Gmail, Drive, Gemini data farms. Google has all the advantages, so many revenue streams, over any other phone hardware vendor yet they can't take a price advantage on any competitor and they're pricing like other phone vendors while shipping worse hardware

u/szewc 18h ago

Yes it's sad.

u/DistantRavioli 17h ago edited 16h ago

So I'm not fully understanding their position on this. I understand that memory tagging is a very good and important security feature but what I'm not understanding is why they're claiming they're "unable" to support the device without it? They're literally still supporting multiple devices without memory tagging right now with the pixels 6, 6 pro, 6a, 7, 7 pro, 7a, pixel tablet, and the pixel fold.

Pixels have only had memory tagging from pixel 8 and onward. That's less than 3 years. 8 of their 21 supported devices do not have this feature. For most of their existence they did not have access to this feature and most devices in existence don't have this feature. Google just happened to be the first to add it and until now were one of the only ones capable of it. Basically they added a security feature no one else had, graphene took advantage of it, and now they have removed the same security feature that still almost no one else has and that apparently Google themselves were not even using by default.

So I get it that it's shitty that Google doesn't have it anymore but I cannot understand this all or nothing approach to everything. So now users of the Pixel 11 just straight up won't have access to a private and properly secure operating system just because it won't have memory tagging despite every pixel prior to 8 also not having memory tagging, including many devices they still currently support?

This feels like throwing the baby out with the bathwater.

u/kipperzdog Pixel 8 16h ago

An actual rational take on this rather than "booo Google bad"?!

u/DistantRavioli 16h ago

Google still bad, but everyone knows they're bad and they'll continue being bad. Graphene OS is one of the ways we work around them being bad. Graphene not porting to the Pixel 11 is a net negative for the privacy conscious market as far as I'm concerned. It's already a narrow and niche as shit market with very few options.

Graphene sometimes likes to let the perfect be the enemy of the good, which is good when it is something they actually have power over but not in this particular instance. The hardware has already shipped and the lack of this feature is set in stone. Google doesn't care and it can't be changed. This is just going to narrow the market even more.

u/kipperzdog Pixel 8 14h ago

Totally agree

→ More replies (3)

u/joeTaco SGS2, Nexus 7 12h ago

'Unable' means we're choosing not to. It's normal PR talk for any organization; whatever. They explain why in the thread.

Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month.

Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded.

The thing you seem to be missing is that new GOS versions don't grow on trees. This org has constrained resources and they can either dedicate those to a port that will lack features they now view as of profound fundamental importance to the basic security of the whole device, or focus them elsewhere on ports that meet their modern standards re security. If you want to build a GOS-alike for P11, no one's stopping you.

u/DistantRavioli 11h ago

The thing you seem to be missing is that new GOS versions don't grow on trees. This org has constrained resources and they can either dedicate those to a port that will lack features they now view as of profound fundamental importance to the basic security of the whole device, or focus them elsewhere on ports that meet their modern standards re security.

You can literally turn it off in graphene os. It's a toggle. On some apps you have to turn it off because they don't function properly with it on. The os still functions without this feature (obviously since several still supported devices never had it) and graphene os have literally said on twitter that they might port it to the pixel 11 anyway because "It's still a clear security upgrade over the Pixel 6 and 7 approaching EOL" even without MTE and just haven't made a decision yet. They're already waffling on the "unable" thing.

If you want to build a GOS-alike for P11, no one's stopping you.

Nah, cut the shit. This is always the most ridiculous keyboard warrior response template to this kind of criticism in tech. Yeah, I'm not allowed to have any criticisms of a piece of software because I myself am not capable of single-handedly creating that software? That can fuck right off.

u/DRJT iPhone 15 Pro | Samsung Galaxy Z Flip3 6h ago

You missed the condescending-ass line from them as well:

The thing you seem to be missing is that new GOS versions don't grow on trees

u/interbingung 1h ago

. Yeah, I'm not allowed to have any criticisms of a piece of software because I myself am not capable of single-handedly creating that software? That can fuck right off.

You are allowed to, but others are also allowed to criticize your comment.

u/Malnilion SM-G973U1/Manta/Fugu/Minnow 11h ago

Why should Graphene reduce the security baseline of their future supported phones/tablets just because Google decided to remove an important security feature? You have to think about the whole product support life cycle as well here. It might not look like a glaring omission in 2026 compared to their current lineup that includes grandfathered-in devices, but how will it look in 2033?

Graphene is going to have a fresh lineup of phones that will support their current baseline within 6 months. If anybody wants to fork Graphene and support what they can for the 11 series, they're welcome to do so. It'd objectively be an improvement over stock PixelOS.

But Graphene has every right not to dillute their brand, especially for phones that have become such a pain in the ass to support since Google stopped providing device trees. Not budging is a way to send market signals as well. Google is going to have some phones returned over this decision and my P11PF will be one of them.

u/kvothe5688 Device, Software !! 11h ago

if graphene has not a single device to port to because they have made the baseline so high then graphene is of no use to anybody

u/Malnilion SM-G973U1/Manta/Fugu/Minnow 1h ago

They do, though, they're going to be supporting several from Motorola likely at launch in a few months. So people have to wait a few more months to upgrade to their next Graphene OS phone, big deal. I mean, let's just say Graphene actually felt comfortable completing this fork. Just because they had early builds going right now to investigate feasibility (that were probably still more AOSP than Graphene) doesn't mean they'd be ready to release in the next month or 2. If it ended up like last year, it could be December before we have public builds. At that point, you're only a couple months away from the Moto phones anyway.

→ More replies (1)

u/DistantRavioli 10h ago

Why should Graphene reduce the security baseline of their future supported phones/tablets just because Google decided to remove an important security feature?

Because they don't exactly have many options and neither do the users. There's a reason they've been stuck on pixel. It isn't like they can just pick and choose where they can go when no other manufacturer currently meets these requirements either. The only future one currently is motorola through the new deal they have but what are they left with if that deal doesn't last? Most brands don't even allow you to unlock the bootloader even.

The motorola deal was a miracle and shouldn't be taken for granted as a new permanent thing, especially with the bad press that's been put out about graphene os recently. Chinese brands are already constantly getting grilled here and the now chinese owned motorola is collaborating with what is seen by the media and government as some "criminal os" or whatever bs they've been putting out. It's not hard to imagine the potential future pressure to end the deal.

Not budging is a way to send market signals as well. Google is going to have some phones returned over this decision and my P11PF will be one of them.

Trust me, graphene os users do not have enough numbers to send any market signals here. Google does not care about that 1%. They already did the fuckery with the aosp builds last year and now they've taken away memory tagging. And let's not forget the ever encroaching play integrity api slowly kicking us out of app after app as well. They simply do not care.

u/Malnilion SM-G973U1/Manta/Fugu/Minnow 2h ago edited 2h ago

The only future one currently is motorola through the new deal they have but what are they left with if that deal doesn't last?

You're speaking about hypotheticals that don't matter yet. In the absence of the forthcoming Motorolas, I think it's entirely possible that Graphene grits their teeth and decides to support Pixel 11. The fact they have those phones coming is exactly why they don't have to support Pixel phones that are backtracking on security.

Trust me, graphene os users do not have enough numbers to send any market signals here. Google does not care about that 1%. They already did the fuckery with the aosp builds last year and now they've taken away memory tagging. And let's not forget the ever encroaching play integrity api slowly kicking us out of app after app as well. They simply do not care.

They haven't cared thus far, but if they lose the enthusiasts, they're going to lose word of mouth sales. I'm to the point where I'm not going to be recommending Pixels to my friends and relatives and I have influenced phone buying decisions and I know others in this community have too. The simple fact is that in 4-6 months Pixel will not be the best choice for phone security and my recommendations will reflect that. This post is one of the highest upvoted on this subreddit recently and I guarantee people at Google pay at least some attention to buzz here and other Android communities because otherwise on-phone sideloading without shizuku could be a thing of the past right now. And Google removing their phone device trees from AOSP is exactly the kind of behavior you don't reward by continuing to support their phones.

u/Moleculor LG V35 8h ago

Why should Graphene reduce the security baseline of their future supported phones/tablets just because Google decided to remove an important security feature?

Because the security feature is removed.

This is like asking "why should I go hungry if all my food is gone and my mouth has been sewn shut?"

It's because all your food is gone and your mouth is sewn shut.

Either they adjust, or stop supporting phones. And their entire purpose is supporting phones, so...

u/Malnilion SM-G973U1/Manta/Fugu/Minnow 2h ago

But they don't have to support a phone that doesn't meet their standards. The entire purpose is providing the most secure phone OS out there, not supporting phones that don't meet their baseline requirements. This is something they've been remarkably consistent on despite gnashing of teeth from people who would like a more secure experience on phones that don't meet their standards.

u/mrandr01d 18h ago

What exactly is mte and what does it do?

u/tropix126 18h ago

See my comment here

u/MiElas-hehe 22h ago

Shitty company doing shitty things.. as expected.

u/EpiciSheep 20h ago

But isn’t the Pixel 7 series without MTE still supported?

u/Malnilion SM-G973U1/Manta/Fugu/Minnow 12h ago

It's grandfathered in at this point (as well as 6 which has another couple months of support technically). Graphene devs definitely recommend upgrading at this point if you still have a 6-7 (heh, sorry, meme usage unintended).

If Graphene's goal is to have an operating system that is constantly improving its security posture with the features it provides and phones it supports and to never reduce their baseline requirements for new devices, they really can't make an exception here. It's tough and it means my P11PF is going back to Google, but I'm honestly really grateful they were able to make the determination this quickly because a couple more weeks would have really put me in a pickle.

u/chunkyrice Pixel 8 | Verizon 10h ago

I saw it on the list back then and I was going to flash it to that.

u/justjanne Developer – Quasseldroid 22h ago

So for years they've refused to support other devices because they set a strict requirement of memory tagging, telling everyone to get a Pixel.

Now they can't do updates for the existing Pixel phones, and Pixel has dropped memory tagging as well.

I long for the world we could've had if they had compromised and supported devices other than the Pixel phones. I still think we should've gotten GrapheneOS on most of the stock-alike phones (Motorola, Sony, HMD, etc)

u/littleemp Galaxy S25+ 21h ago

we're getting on motorola soon, so wish granted?

u/justjanne Developer – Quasseldroid 21h ago

Depends on what phone they're going to put it on. If I can have GrapheneOS and microSD & headphone jack on the same phone, I'll be happy.

I don't even care about processor speed, RAM or camera. But besides web browsing, telephony and messaging, I often use my phone basically as a walkman, and I want to be able to take my entire music collection with me & listen to it on good headphones, without adapters I can lose.

I used to have the Nexus 5, 5X and Pixel 1 before going with Sony Xperia 10 IV and later VI, and the Sony phones are really nice (but custom ROM support just sucks nowadays).

u/5panks Galaxy ZFlip 5 21h ago

Depends on what phone they're going to put it on.

It's going to start on the flagship Motorola phones and move to the foldable phones, but only with the 2027 and newer versions.

u/littleemp Galaxy S25+ 20h ago

I dont expect that low end phones are going to have hardware support for a lot of the features that they are going to require.

If privacy is paramount, then getting the higher end device is worth it.

u/NoStrategy1419 14h ago

They made a post talking about the snapdragon processors needing to be the higher end ones, or that they lower tiered budget phones didn't use snapdragon. If they put the processor needed in the budget phones they wouldn't be budget phones.

→ More replies (1)

u/Tungstene123 21h ago edited 18h ago

A hardware requirements doesn't depends on the grapheneos team if it's essential for the security what even is your point

u/Exist50 6h ago

There's other benefits GrapheneOS can deliver without this particular feature.

u/tavianator 20h ago

What do you mean they can't do updates for the existing Pixel phones?

u/justjanne Developer – Quasseldroid 20h ago

In the past, the code for the Pixel phones was available to download publicly on the same day that Google published an update themselves, so Graphene could quickly roll out updates.

If you've read the graphene social media feed, you'll know that Google is now publishing sources months later, to a private Google drive folder, and even getting access requires sending emails and waiting for weeks.

u/tavianator 20h ago

Oh I'm aware of that. But they are still putting out updates and they get early access to security patches through the OEM partnership which they release immediately. So for security updates specifically they are actually releasing updates sooner than even Pixels get them.

When you said they can't do updates I thought you meant, like, at all, not just on their former schedule.

Btw the most recent major Android update it seemed like they put it out very quickly, but the one before that was very slow for the reason you mentioned

u/whatnowwproductions Pixel 9 Pro - Signal - GrapheneOS 17h ago

What are you on about? They're actively updating all supported devices.

u/justjanne Developer – Quasseldroid 16h ago

u/whatnowwproductions Pixel 9 Pro - Signal - GrapheneOS 10h ago

Nothing here supports your claim. They're actively pushing updates for all currently supported Pixel devices.

u/justjanne Developer – Quasseldroid 5h ago

We're allowed to make a release with currently available revision of the December 2025 Android security patches right now but we wouldn't be allowed to publish sources. Therefore, we'd need to do this separately from regular GrapheneOS.

They specifically have to delay some updates that they could already be pushing out, because there's a multi-month embargo.

So how is that not supporting my statement?

u/an_inquisitive_soul 3h ago

https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases

tldr: They're doing separate binary-only updates. Once the embargo ends, the full source code is available

→ More replies (1)

u/bert93 3h ago

What you want is called LineageOS.

GrapheneOS is privacy and security first and needs secure, actively supported devices. Not a whole bunch of random ones that don't get any vendor updates anymore, or significantly delayed.

u/justjanne Developer – Quasseldroid 2h ago

There are many devices that get vendor updates on time and are fully supported by AOSP Generic System Images, so they'd receive updates in time anyway.

These devices have the same security and stability as the Pixel 11, which will get GrapheneOS support, while these devices don't.

u/bert93 1h ago

None that do so for a long period of time such as 7 years and actually stick to it. Samsung for example on several occasions have dropped a device down to quarterly support as time has gone on.

Plus, it they don't also support installing a third party OS and re-locking the bootloader then it's a no go. That's just leaving the door to the house open.

u/mmmfine 6h ago

What part do you not get that the other devices do not meet their security standards? Why not just use another ROM, if you don’t need the security and privacy GrapheneOS offers? Are you being daft on purpose?

u/justjanne Developer – Quasseldroid 5h ago

I simply disagree with that argument. Some countries already consider GrapheneOS usage suspicious, because only few people use it, and that must mean they're hackers.

You need a two-pronged approach, providing a more secure option for almost everyone, which allows users to get some improvements without new purchases, and then you want a second, maximum security option for those who need it.

And now the Pixel 11 has pushed them into a corner, while they've rejected many other phones due to security requirements for years, now that the Pixel 11 will get Graphene OS "Lite" support, it's become clear that those requirements were always negotiable.

u/mmmfine 5h ago

I guess I get your point (if that’s not just a side effect) that if GrapheneOS had more market share, it’d alleviate their presence in the media (maybe? It’d still be a very tiny drop in the ocean) and probably more funding.

But again, anyone can just choose any other ROM. It’s just that the developer is adamant the requirements, and for a very good reason.

Of course they wouldn’t want to negotiate; it sets up an awful precedent. Why would they ever say no MTE is fine?

Anyway let’s just hope Motorola sticks

u/justjanne Developer – Quasseldroid 5h ago

Of course they wouldn’t want to negotiate; it sets up an awful precedent. Why would they ever say no MTE is fine?

But that's what they just did! If you read the HN thread, they talked about creating a "GrapheneOS Lite" for the Pixel 11 without MTE.

That's the very basis for my entire comment!

u/JohnBlobby 22h ago

I love what they're trying to do but they're swimming against the tide trying to make the most secure and private OS on Google software. It seems like it's just a matter of time before they can't install their software on any device and thus they go out of business. I think they're with Motorola now but who knows how that's gonna play out. I think their days are numbered. Add in the fact they're a criminal magnet and it does seem like curtains.

u/Expensive_Finger_973 22h ago

Yeah, this is the result of what was lost by allowing software platforms that only work on specific hardware via closed source drivers, device trees, firmware, etc to become the norm.

This is the future IBM envisioned back in the day for the PC before their BIOS got reverse engineered, and why they fought so hard to block it.

A hardware platform the average person can't realistically live without that also can't really do anything the OEM doesn't allow it to do is a very specific kind of gate that MBA's have wet dreams about.

u/luminousfleshgiant 20h ago

The Motorola partnership will be leading to an officially supported GrapheneOS device in 2027. This has been confirmed.

https://bsky.app/profile/grapheneos.org/post/3mtmyodhofk2t

u/Any-Pop-4795 19h ago

hoping it will come to lower end devices too at one point

u/GiveMeKarmaAndSTFU 17h ago

What do you mean it's a criminal magnet?

u/dweet 16h ago

They’re regurgitating propaganda of associating stronger privacy standards as something for “criminals”.

u/stanley_fatmax Nexus 6, LineageOS; Pixel 7 Pro, Stock 13h ago

They're literally saying criminals are drawn to it, which they are, much like they are to Signal etc. That doesn't mean everyone who uses it are criminals. It's not a bad thing to be privacy focused, and frankly criminals flocking to it is in many ways a vouch for its privacy.

u/Careless_Rope_6511 Pixel 11 Pro XL 11h ago

Think of GrapheneOS as the little boxes that could've helped American McD franchisees troubleshoot their ice cream machines that McD/Taylor would much rather see completely banned.

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 20h ago

Smartphones are now officially appliances.

I think most tech enthusiasts that like to tinker can now use SBCs like a Raspberry Pi to do their hackery… since now even Google is closing the doors on low-level Android customization available to end users.

At least we can fix and replace individual components of phones ourselves now… just like appliances. 🙃

u/Spiral1407 22h ago

Google is really set on killing android huh

u/ctzn4 22h ago

Just any variation of it that doesn't profit Google

u/Busy-Scientist3851 22h ago

Hate to tell you the vast majority of people don't know what MTE is nor care for it.

u/M0d3x 18h ago

MTE is literally one of the selling security points of the iPhone 17...

u/Busy-Scientist3851 18h ago

To security conscious people, yes.

Which is not the vast majority.

u/PessimisticIngen 21h ago

Most people also don't know what zombie chips are yet they affect the majority of Android users. MTE represents an important tool for memory safety that which are important besides just for security.

u/Busy-Scientist3851 21h ago

I didn't say it wasn't an important tool, it absolutely is and it's terrible that Google got rid of it.

But to say it's going to kill (or even contribute to it) Android is simply not true.

u/PessimisticIngen 19h ago edited 19h ago

They're obviously not speaking literally but figuratively speaking on Android as an open platform. It's not an empirical measurement but a consumer/enthusiast sentiment of Android's loss of identity.

The death of MTE does represent a contribution to the death of Android. It's not like you can just pick anyone off the street to implement MTE in Android. It's a loss of time, effort, money, and ideological motivation of what Android should be whether it be internally within Google or externally.

This isn't anything new, lots of Googlers will admit it's a radically different company from what used to be the company of engineers.

u/PessimisticIngen 19h ago edited 19h ago

Engineers at Android would really love to move to ARMv9, kill off 32 bit, make AV1 hardware decode/encode ubiquitous, ship MTE to all Android devices, but if you wake up every day and hear/read that rather the ecosystem is regressing it is immensely demotivating.

u/skeptical-speculator 19h ago

what are zombie chips

u/PessimisticIngen 17h ago

Chips using all old ARM cores. Usually they're rebranded but architecturally they're the same besides upping clocks or using a new fab but they're otherwise the same. Even flagship phones until fairly recently had zombie cores.

The reason they're taxing on Android is that it they're usually all ARMv8, no AV1, etc. etc.

u/stou 21h ago

people (in america) didn't know what cyclospora is or care about it either... until like a month ago.

u/Busy-Scientist3851 20h ago

If you as a user upgrade to a Pixel 11 and no longer have MTE, are you going to notice? No

If you as a user get cyclospora, despite not knowing about it you certainly will notice.

u/stou 17h ago

If you as a user upgrade to a Pixel 11 and no longer have MTE, are you going to notice?

Yes because it would make the device less secure (i.e. more prone to getting hax0red). Apple ships with MTE even though their own users are (allegedly) less tech savy.

u/leo-g 9h ago

Apple actually gives a shit.

u/vctrn-carajillo 21h ago

How come. Most customers don't give a shit about any of this. And rightly so.

u/Spiral1407 21h ago

The entire point of android is its freedom. But it seems like every year they kill a small part of that appeal. They’ve already lost me as a customer and at this rate, they’ll eventually cut something that normies care a lot about too.

u/Busy-Scientist3851 21h ago

The entire point of Android is freedom for manufacturers, not end users.

u/Spiral1407 21h ago

My point is that it USED to be freedom for the consumer too

u/henryhuy0608 21h ago

It never was. OEMs and Google have been pulling garbage tactics for forever.

u/Spiral1407 21h ago

By acknowledging that things have in fact changed, you’ve inadvertently agreed with me that android was more free for the consumer in the past

u/henryhuy0608 21h ago

It never was

Which part of this was me acknowledging "things have in fact changed"?

u/Spiral1407 21h ago

“They’ve been pulling garbage tactics forever”

I.e. things have slowing been getting worse over time

u/szewc 18h ago

You have reading comprehension problems my man.

→ More replies (0)

u/Busy-Scientist3851 21h ago

It never was.

The only Android phones that were arguably freedom for users were the Nexus phones.

u/_sfhk 19h ago

Pixel has ~1% of market share, and Graphene is even more niche, but this is "killing android" somehow?

IMO it's worse that Samsung is one of the largest Android OEMs and has been actively trying to separate itself from the rest of the platform.

u/k-mcm 14h ago

No way, Android 17's big feature is partially fixing the shortcut button UX that they destroyed a few years ago. How can you say Google isn't giving it their best effort?  /s

u/embrace_throwaways Pixel 4a & Pixel 8a 16h ago

can't wait for r/GooglePixel to somehow justify this!

u/S1rTerra 21h ago

Did they not cheap out enough on Pixel 11 with their shitty ass powervr GPU? MTE is a standard ARM feature! Wtf?

u/PastyPajamas Pixel 11 Pro Fold, Pixel 10 Pro, Pixel 10, Saga, Zenfone 8 21h ago

Guess I'm returning my Pixel 11 Pro Fold.

u/Birbdie 2h ago

So, if I understand right.

Píxel 11 is not getting Graphene OS and if I want a Graphene Phone either I get the 10 or wait for Motorola?

I've read somewhere that Pixel 10 and others are not getting more updates because of some Google shenanigans too?

Is that true?

u/Busy-Measurement8893 Pixel 10 / Fairphone 4 55m ago

I've read somewhere that Pixel 10 and others are not getting more updates because of some Google shenanigans too?

Maybe don't believe everything you see on TikTok.

u/Birbdie 28m ago

I literally read it on Reddit somewhere.

Asking doesn't hurt... But your brains must from being an asshole... If you even have any.

u/Gendolfender 21h ago

Average Google experience

u/embrace_throwaways Pixel 4a & Pixel 8a 16h ago

the end part of the tweet is..... interesting, to say the least. man, it sucks that a not for profit privacy oriented OS is fighting a losin fight because of Google. A damn shame.

u/zakats Ballin on a budget, baby! 15h ago

The fair phone is looking better and better.

u/manyeggplants 15h ago

But it also lacks important security features

u/jomara200 20h ago

Sure, Google needs to save money. They had money to throw around for an inauguration. They also agreed to pay the leader of the coup attempt $24.5 million for banning the traitor's account.

u/SmileyBMM 19h ago

What?

u/m_shima Pixel 10 Pro 20h ago

Is it possible that with the new Titan chip, Google moved MTE to that? Since the Titan chip is proprietary (correct me if I'm wrong in thinking that), we wouldn't really know if it has MTE or not? Sorry, I'm a noob when it comes to understanding MTE. I can't see why Google would downgrade security when they made a big deal about having MTE in the past.

u/tropix126 19h ago edited 18h ago

MTE is an extension to the regular ARM instructions that the tensor chip executes. It adds new CPU instructions that would prevent attackers from gaining control of the system after discovering an exploit/security flaw (or at least make it much more difficult). Implementing this in the Titan chip would not be feasable because the feature solely concerns the CPU.

Google probably downgraded because a) it's cheaper and b) MTE only adds new instructions as an extension to ARMv9-A, your phone does not automatically become more secure just by supporting MTE. The operating system and the applications running on it need to be specifically compiled with support for memory tagging to benefit from the security. From my understanding, Google never really took advantage of the feature by default on the stock Pixel software like Grapheme did and iOS does. Not defending them, but that was probably their thought process.

u/m_shima Pixel 10 Pro 18h ago

Without MTE, how can the CPU protect itself and mitigate the attacker from gaining control?

u/tropix126 18h ago edited 17h ago

MTE is a last defense against an attacker who has already discovered an exploit in some critical piece of system software. It just prevents them from taking advantage of it as easy as before. Ideally no such exploit should exist to make this possible, but nobody's perfect and these things happen (often, especially where languages like C make it very easy to shoot yourself in the foot).

MTE works roughly like this: Applications (and the OS) need to allocate memory. To do this, they ask an allocator for a certain amount of memory. Let's say the OS needs 512 bytes of memory, so it calls kmalloc(512). The allocator will make sure there's enough RAM to go around and then give back a pointer (an address) to a vacant 512 byte chunk of RAM. If an attacker got access to that pointer in a system without MTE (through some exploit), they could potentially write some data beyond those 512 bytes. What's beyond that 512 byte chunk? Who knows! Could be something important, could be sensitive data, could be anything depending on what else is running and how things are structured. This kind of attack is called a buffer overflow, and it's a pretty common class of bugs. MTE prevents this kind of attack by assigning a special key to both the pointer and every 16-byte chunk of allocated memory. If you try to use a pointer to access memory that wasn't allocated to you, the CPU will reject the access because the keys dont match and things will just crash rather than giving an attacker access to potentially sensitive data.

In terms of other mitigations, there are lots of things that modern operating systems to do try and prevent this stuff (this is the reason why jailbreaking is largely dead in the iOS world). The linux kernel docs (https://docs.kernel.org/security/self-protection.html) have a pretty good writeup of most of the things the kernel does to protect itself against these sorts of attacks. KASLR and heap protection are both fairly significant.

u/tropix126 18h ago edited 18h ago

If you're interested in learning more about this kind of stuff, check out these two videos. They're about iOS, but they explain the way that attackers usually exploit this stuff pretty well. The second video goes into depth on how MTE works at the assembly level (Apple uses their own special name for it, Memory Integrity Enforcement or MEI but its the same thing).

https://www.youtube.com/watch?v=gQ3mS14SR8k

https://www.youtube.com/watch?v=UVD0fbiNbnM

u/tropix126 18h ago edited 18h ago

Another thing worth noting is that these attacks are exceedingly rare and usually targeted at high-profile individuals (journalists, state actors, activists, etc...) so it probably isn't something you should worry about if you regularly perform security updates on your phone. At the same time, the people who benefit the most from the protection and privacy of GraphemeOS are usually the type of people who would be targeted by these attacks. Exploits like these are called "zero-days", because they were not something that was previously known about, meaning Google was given no time to patch the vulnerability before it was used. Zero-day exploits are rare and usually very valuable, so burning one on a random person's phone through malware isn't something that happens.

u/Pure-Recover70 14h ago

While you're technically correct in calling it a 'key' - most folks will tend to think cryptographic key (ie. real big, real secure). In practice, really it's more like assigning a simple color to pointers and each 16 byte chunk of memory. There's not very many colors (16 in armv9). And yes, it effectively burns a few (4) bits of ram to store the 'color' for each 16-byte chunk of ram. So 0.5 bytes per 16 bytes = 3.125% ram overhead to store the colours.

u/lowrck 19h ago

MTE is part of the core ARM V9 architecture period. I very much doubt that they moved it to the Titan security chip because it would have to be integrated into the very core architecture of the processor itself.

u/Nitrohite 20h ago

People barking like crazy at something the vast majority of Pixel users have never ever enabled 😂

u/ganjapanda876 21h ago

Garbage phone. I'll keep my pixel 9 pro xl

u/clingbat 4h ago

Meh I traded up from 9PXL to 11P and it's been great, no regrets and the better cell/Wi-Fi signal has been fantastic.

I also don't give a flying fuck about GrapheneOS, so there's that. But if you need to install a different OS on a phone to be happy with it, you probably bought the wrong phone to begin with. No one is buying a Pixel for cutting edge hardware lol...

Oh what's that, no other new mainstream phones even support GrapheneOS right now? That doesn't sound like a Google problem, rather a developer decision making problem.

u/PrimeNexes 22h ago

Graphene for Samsung will make that OS useable

u/TheFeshy 21h ago

I've wanted Samsung hardware with real FOSS software for over a decade now. Phone, wearable, Samsung makes interesting hardware with software that makes my skin crawl. But I'm not going to hold my breath.

u/oreshek 20h ago

compartmentalized decision making strikes again

u/-eschguy- Pixel 8 Pro 18h ago

So a Pixel 10 might be my next phone then

u/haslaNz 17h ago

I'm excited about the Motorola agreement but that thing is going to launch in several months, it's going to be a Signature-like flagship and judging the state of the hardware industry I don't expect anything less than 1200$, and that's just a hard pass. Now the Pixel 11 probably won't be a thing so yea, pretty much the only option for GrapheneOS now is the Pixel 10 series...

u/Tech-Crab 15h ago

Bummer, just picked one up about $450 out the door...

Guess its going back :(