
GrapheneOS says it may abandon support for Google’s Pixel 11 series after discovering that the new devices appear to lack usable support for ARM Memory Tagging Extension (MTE).
MTE is a hardware security feature the privacy-focused Android project relies on extensively to mitigate memory corruption exploits.
The GrapheneOS team disclosed the issue on X after spending roughly a week on a partial Pixel 11 port. According to the project, MTE support is missing at the software and firmware levels and is “near certainly” absent from the hardware itself, preventing the team from completing the port to its normal security standards.
MTE allows memory allocations to be tagged so that invalid or unexpected memory accesses can be detected before they are successfully exploited. GrapheneOS has used hardware MTE throughout much of its operating system since the Pixel 8 introduced support in October 2023, including in the kernel, hardened_malloc, and standard system processes.
GrapheneOS is an Android-based operating system focused on security and privacy, best known for supporting Google Pixel hardware. Its hardening measures go beyond stock Android in several areas, including exploit mitigations, sandboxing, faster integration of security patches, and tighter control over application permissions.
The project says the loss of MTE would significantly weaken protection against many remote and local memory-corruption attacks when a device is already unlocked, a state commonly referred to as After First Unlock (AFU).
Google has not provided GrapheneOS with an explanation for the apparent change. The project believes cost-cutting is the most likely cause, although it acknowledged that an undisclosed hardware flaw remains another possibility. GrapheneOS said it had previously heard from a Google insider that MTE could be removed from a future Pixel generation.
The Pixel 11 does introduce other security improvements. GrapheneOS highlighted post-quantum ML-DSA signatures for verified boot, the replacement of Samsung Shannon IMS components with AOSP IMS, and the new Titan M3 security chip, which it expects to provide stronger resistance to data extraction while a phone remains in the Before First Unlock state.
However, the project argues those gains do not compensate for losing MTE. It currently recommends Pixel 8, Pixel 9, and Pixel 10 devices instead, saying they provide better overall security when running GrapheneOS.
The discovery could also accelerate GrapheneOS’s move away from Google hardware. Pixel devices stopped serving as Android Open Source Project reference devices with Android 16, and GrapheneOS says supporting them has become more difficult as a result.
The team is now considering skipping the Pixel 11 generation entirely and focusing development resources on its upcoming Motorola partnership. GrapheneOS says the planned Motorola flagship, expected in 2027, will meet its hardware security requirements, including MTE support.
For users who bought a Pixel 11 specifically for GrapheneOS, the project currently recommends returning it if still possible.






Leave a Reply