{"id":8406,"date":"2026-09-18T07:17:00","date_gmt":"2026-09-18T14:17:00","guid":{"rendered":"https:\/\/catbradley.io\/?p=8406"},"modified":"2026-09-18T07:17:00","modified_gmt":"2026-09-18T14:17:00","slug":"grapheneos-isnt-happy-with-google-over-pixels-widening-head-start","status":"publish","type":"post","link":"https:\/\/catbradley.io\/?p=8406","title":{"rendered":"GrapheneOS Isn&#8217;t Happy With Google Over Pixel&#8217;s Widening Head Start"},"content":{"rendered":"<figure><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/2026\/09\/grapheneos-unhappy-banner.png\" alt=\"grapheneos angry with google banner\" loading=\"lazy\" \/><\/figure>\n<p>Google&#8217;s <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/pixel\/2026\/2026-09-01\">September 2026<\/a> Pixel Update Bulletin contains patches beyond what&#8217;s in that month&#8217;s regular <a href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-09-01\">Android Security Bulletin<\/a>. According to <a href=\"https:\/\/grapheneos.org\/\" rel=\"noreferrer\">GrapheneOS<\/a>, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.<\/p>\n<p>None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.<\/p>\n<p>And at this rate, these won&#8217;t reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.<\/p>\n<p>The project <a href=\"https:\/\/grapheneos.social\/@GrapheneOS\/117282080803799576\">is characterizing this<\/a> as Google &#8220;<em>gatekeeping security patches to the standard Android platform code from Android OEMs<\/em>.&#8221;<\/p>\n<h2>The complaints<\/h2>\n<p>GrapheneOS says <a href=\"https:\/\/developer.android.com\/about\/versions\/17\/qpr1\/release-notes\">Android 17 QPR1<\/a> shipped new developer APIs that never made it into AOSP. This is something they claim hasn&#8217;t happened since Android&#8217;s Honeycomb days.<\/p>\n<p>Google&#8217;s <a href=\"https:\/\/developer.android.com\/sdk\/api_diff\/37.1\/changes\/changes-summary\">API diff report<\/a> backs this up. Comparing Android 17 to QPR1 shows one new package, <code>android.hardware.hid<\/code>, plus changes across sixteen others, including <code>android.media<\/code>, <code>android.os<\/code>, <code>android.provider<\/code>, <code>android.telecom<\/code>, and <code>android.view<\/code>.<\/p>\n<p>GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn&#8217;t have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.<\/p>\n<p>On top of all that, there&#8217;s <strong>a compliance issue that seems to be recurring<\/strong>.<\/p>\n<p>Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (<em>CD1A.260905.001.A1<\/em>) on September 1, and access only came through more than two weeks later.<\/p>\n<h2>Why this is worrying<\/h2>\n<p>None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code\u2014each is the kind of thing that could pass as a one-off.<\/p>\n<p>Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking <a href=\"https:\/\/en.wikipedia.org\/wiki\/GNU_General_Public_License\">GPL<\/a> compliance it&#8217;s required to meet.<\/p>\n<p>Don&#8217;t even get me started on <strong>what they are doing to the Android app ecosystem<\/strong>.<\/p>\n<p>Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, <a href=\"https:\/\/itsfoss.com\/news\/new-android-sideloading-rules\/\">to register with them<\/a>. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.<\/p>\n<p>Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (<em>classic <\/em><a href=\"https:\/\/dictionary.cambridge.org\/us\/dictionary\/english\/scare-tactics\"><em>scare tactics<\/em><\/a><em>, btw<\/em>).<\/p>\n<p>GrapheneOS is one of dozens of organizations that signed onto the <a href=\"https:\/\/keepandroidopen.org\/\">Keep Android Open<\/a> campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.<\/p>\n<p>If you ask me, this Big Tech company is doing what&#8217;s regrettably natural for it, clamping down open access to things so that its competition cannot benefit.<\/p>\n<p><em>Via: <\/em><a href=\"https:\/\/www.androidauthority.com\/grapheneos-android-17-qpr1-security-patches-comments-3712218\/\"><em>Android Authority<\/em><\/a><em>.<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/feed.itsfoss.com\/link\/24361\/17466072.gif\" height=\"1\" width=\"1\" \/><\/p>","protected":false},"excerpt":{"rendered":"<p>Google&#8217;s September 2026 Pixel Update Bulletin contains patches beyond what&#8217;s in that month&#8217;s regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[1],"tags":[],"class_list":["post-8406","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rss"],"_links":{"self":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/8406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8406"}],"version-history":[{"count":0,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/8406\/revisions"}],"wp:attachment":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}