GrapheneOS Says Google Is Keeping New Android 17 Security Features from Other Phones

GrapheneOS says that by withholing new security features in Android 17 QPR1 from AOSP, Google wants to ensure its own Pixel OS has the upper hand first

Abubakar Mohammed profile pictureby Abubakar Mohammed
Link Copied
copy link iconcopy link icon
Pixel 11 Pro from the back in Frost Blue colourway

Image Credit: Beebom Gadgets

Summary

  • GrapheneOS has fired at Google for not merging Android 17 QPR1 security and privacy APIs with AOSP.
  • The secure operating system manufacturer has accused Google of anti-competitive practices.
  • Google is essentially giving Pixel OS the upper hand in security, leaving behind other Android manufacturers.
Click Here to Add Beebom Gadgets As A Trusted SourceGoogleAdd as a preferred source on Google

GrapheneOS has accused Google of deliberately withholding crucial APIs and Security fixes from AOSP in the Android 17 QPR1 update. The decision affects Android manufacturers, with the new security measures potentially never arriving on phones other than Google Pixel devices.

Google Is Withholding AOSP Code

According to GrapheneOS, Android 17 QPR1 marks the first time since Android Honeycomb that Google has introduced new developer APIs without simultaneously publishing the corresponding code to AOSP.

GrapheneOS on X explaining lacklustre Android 17 QPR1 security APIs
GrapheneOS on X explaining lacklustre Android 17 QPR1 security APIs

This means that the new APIs that promote better privacy and security can never be implemented on other Android smartphones, as Google has officially made them exclusive.

The GrapheneOS team stated they had their code ported prior to the September 15, 2026 release but currently lack permission to publish it. The complaint arrives on top of developers already being forced into the tedious process of backporting Pixel firmware, userspace drivers, and HALs directly to the older Android 17 framework.

This is because Google has essentially stopped publishing device trees, source code and binaries for Pixel phones, essentially attempting to kill third-party custom ROM support.

However, projects like Graphene and LineageOS have held on, albeit still limited to the Pixel 9 series. As a result of this change, even a year after the Pixel 10's launch, the phones are still not supported by the LineageOS team. 

Critical Security Repercussions

The accusations also extend to critical device safety. The September 2026 Pixel Update Bulletin mentions several vulnerability fixes that are conspicuously missing from the standard Android Security Bulletin.

GrapheneOS calling out Google for dubious practices
GrapheneOS calling out Google for dubious practices

GrapheneOS claims that many of these fixes apply to core platform components used by non-Pixel devices. By holding these ecosystem-wide patches back until the Android 17 QPR2 release in December, Google is giving its Pixel hardware an exclusive security advantage over other Android OEMs.

While GrapheneOS acknowledges that Pixels are still useful for their project due to their baseline security features, they warn that Google's new strategy makes supporting the devices significantly more difficult.

That said, with the upcoming GrapheneOS-Motorola partnership, the project expects its upcoming collaboration to streamline software development, as that partnership will provide direct access to official firmware and driver code.

This is clearly not a good outlook on Google's part, especially considering how the company doesn't hesitate to market Android security and privacy. If anything, these actions suggest otherwise, and delaying new security APIs and features is quite contradictory.

#Tags

android

Recommended For You