Pixel 11 Security Flaw: Why GrapheneOS Dropped Google’s Phones

Not long ago, the GrapheneOS team announced plans to broaden support beyond Google Pixel devices to include select Motorola flagship phones. That expansion highlighted the importance of particular hardware and software features that make a platform like GrapheneOS viable on non-Pixel hardware. However, recent developments indicate GrapheneOS will not move forward with official support for Google’s new Pixel 11 series, owing to a deliberate omission of a critical security capability by Google.

GrapheneOS maintainers report they began work on a port for the Pixel 11 and completed a partial build after roughly a week of effort. Progress stalled because the Pixel 11 lacks support for ARM’s Memory Tagging Extension (MTE) in the software, firmware, and almost certainly the underlying hardware. The GrapheneOS team views MTE as a foundational security layer that their architecture depends on; without it, they say they cannot deliver the platform with the same security guarantees users expect. The team interprets the absence of MTE as a cost-driven choice by the device maker to omit an important security feature.

We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We’re unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money.

To clarify what is at stake: MTE is a hardware-assisted mechanism designed to reduce memory safety vulnerabilities by tagging memory allocations and detecting misuse at runtime. When supported across hardware, firmware, and operating system layers, MTE can mitigate a class of bugs that lead to memory corruption, buffer overflows, and other exploitable conditions. GrapheneOS has relied on such memory-safety improvements since MTE first appeared on recent Pixel models, incorporating the feature into its broader threat model and hardening strategy.

Although MTE can introduce performance and compatibility trade-offs for some workloads and applications, security-focused projects like GrapheneOS prioritize these protections because they significantly raise the bar against certain exploit techniques. For users who value the enhanced protections and privacy posture GrapheneOS offers, that trade-off has been acceptable on prior Pixel generations. With the Pixel 11 lacking MTE, GrapheneOS maintainers have chosen to concentrate their development resources on devices that provide the underlying hardware and firmware support they require.

Given the change in direction, the GrapheneOS team has signaled a renewed focus on alternative hardware partners. Motorola’s recent flagship phones—built around Snapdragon platforms—were already mentioned as targets for expansion, in part because of stronger hardware feature support that aligns with GrapheneOS requirements. This pivot reinforces how critical consistent, cross-layer support for security features is when porting a hardened mobile operating system to new devices.

For users intending to run GrapheneOS on a Pixel device, the safest approach remains to choose a model that includes MTE support and has a proven track record with the project. In practical terms, that means Pixel 8 through Pixel 10 series devices remain good candidates where GrapheneOS support is established or has previously been available. Prospective users should verify current compatibility on GrapheneOS’s official channels before making device purchases, since compatibility information can change as new builds and ports are developed.

Ultimately, this situation highlights a broader tension in consumer device design: balancing cost, performance, and compatibility against security hardening measures that increase resilience to sophisticated attacks. For security-focused operating systems like GrapheneOS, those lower-level hardware and firmware features are not optional—they are central to the project’s ability to provide meaningful protections. Until future Pixel models restore the missing elements or device makers adopt comparable features, GrapheneOS will prioritize hardware options that meet its security requirements.