GrapheneOS has accused Google of deliberately withholding crucial APIs and Security fixes from AOSP in the Android 17 QPR1 update. The decision affects Android manufacturers, with the new security measures potentially never arriving on phones other than Google Pixel devices.
Google Is Withholding AOSP Code
According to GrapheneOS, Android 17 QPR1 marks the first time since Android Honeycomb that Google has introduced new developer APIs without simultaneously publishing the corresponding code to AOSP.

This means that the new APIs that promote better privacy and security can never be implemented on other Android smartphones, as Google has officially made them exclusive.
The GrapheneOS team stated they had their code ported prior to the September 15, 2026 release but currently lack permission to publish it. The complaint arrives on top of developers already being forced into the tedious process of backporting Pixel firmware, userspace drivers, and HALs directly to the older Android 17 framework.
This is because Google has essentially stopped publishing device trees, source code and binaries for Pixel phones, essentially attempting to kill third-party custom ROM support.
However, projects like Graphene and LineageOS have held on, albeit still limited to the Pixel 9 series. As a result of this change, even a year after the Pixel 10's launch, the phones are still not supported by the LineageOS team.
Related Articles

Critical Security Repercussions
The accusations also extend to critical device safety. The September 2026 Pixel Update Bulletin mentions several vulnerability fixes that are conspicuously missing from the standard Android Security Bulletin.

GrapheneOS claims that many of these fixes apply to core platform components used by non-Pixel devices. By holding these ecosystem-wide patches back until the Android 17 QPR2 release in December, Google is giving its Pixel hardware an exclusive security advantage over other Android OEMs.
While GrapheneOS acknowledges that Pixels are still useful for their project due to their baseline security features, they warn that Google's new strategy makes supporting the devices significantly more difficult.
That said, with the upcoming GrapheneOS-Motorola partnership, the project expects its upcoming collaboration to streamline software development, as that partnership will provide direct access to official firmware and driver code.
This is clearly not a good outlook on Google's part, especially considering how the company doesn't hesitate to market Android security and privacy. If anything, these actions suggest otherwise, and delaying new security APIs and features is quite contradictory.
Related Articles























