GrapheneOS accuses Google of gatekeeping Android patches
GrapheneOS says Android 17 QPR1 handed Pixel phones new developer APIs and extra security fixes that no other Android maker has been given until December.

GrapheneOS has pointed a very public finger at Google and accused it of quietly closing Android's front door. In a thread published on 16 September, the privacy-focused Android distribution said this month's Pixel-first release handed Google's own phones new developer APIs and extra security patches that no other Android manufacturer has been given, and that the rest of the industry will wait until December to catch up.
What GrapheneOS says Google has changed
The complaint turns on a release name. GrapheneOS says Android 17 QPR1 is the first release since the Honeycomb era to add new interfaces for app developers without a matching release to the Android Open Source Project, the shared codebase that every other Android vendor builds its software from. Its reading is that those APIs are locked to the Pixel operating system for now and will only reach AOSP and other manufacturers through Android 17 QPR2 in December 2026. Google's own developer reference lists an API difference set between levels 37 and 37.1, which fits with a feature drop that arrived with fresh interfaces attached.
GrapheneOS also argues the change is not accidental. It says QPR1 and QPR3 releases have been Pixel-exclusive since Android 16, while yearly releases and QPR2 still go out to the wider ecosystem. That was a smaller problem when those interim drops were mostly bug fixes. Adding new developer APIs to a Pixel-only release is what turns a scheduling quirk into a two-tier platform.
The security-patch claim, in GrapheneOS's own words
The sharper allegation is about fixes rather than features. GrapheneOS says the September 2026 Pixel Update Bulletin contains additional patches to standard Android platform components used by non-Pixel devices, and that those patches were not made available through the September 2026 Android Security Bulletin or through the preview patches Google offers manufacturers. “Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs but that's what they've started doing,” the project wrote. It says other manufacturers will receive the same fixes in December 2026 with Android 17 QPR2.
What GrapheneOS is doing instead
GrapheneOS says it was ready and still could not ship. Its port to Android 17 QPR1 was finished before the 15 September release, but the project says it does not have permission to publish it yet, so it is backporting Pixel firmware, kernel drivers, userspace drivers and hardware abstraction layers from QPR1 onto Android 17 in the meantime. It also says code requests are dragging: it asked for the CD1A.260905.001.A1 sources on 1 September and was only given access on 16 September. On the patches themselves, it says it can release them early by reverse engineering the code rather than waiting.
The thread sets out what that costs the project. GrapheneOS says Pixels are now “significantly harder to support than many other devices”, that one of the few remaining advantages of Google's hardware has become a disadvantage, and that upcoming Motorola devices will be easier because they arrive with firmware and driver code included. It still plans to support the Pixel 11 series as long as the phone keeps fully functional memory tagging, which it says performs fine and passes the project's tests once enabled.
Our opinion
Android's pitch has always been that the platform is shared: Google does the work, everyone else ships it. What GrapheneOS is describing is the quieter version of the argument Apple and Nvidia settled on their own terms years ago, where whoever builds the platform also decides who gets to be early, and early is where the advantage lives. If the extra fixes really do touch components that every Android phone runs, the delay is not a product decision. It is a maintenance bill handed to every other manufacturer and dated December.
The part worth watching is the workaround. Shipping security fixes by reverse engineering a binary because the source is not available until the next quarterly drop is a fragile way to run a supply chain, and to its credit GrapheneOS says plainly that this is what it is doing. Google could settle the argument cheaply by saying which bulletins changed which shared components, and when everyone else will get them. Until then the accusation stands unchallenged, and the most security-conscious Android project in the room is telling its users that Google's own flagship hardware has become the awkward one to support.
- GrapheneOS published the thread on its official account on 16 September 2026
- It says Android 17 QPR1 is the first release since Android Honeycomb to add new app-developer APIs without a release to the Android Open Source Project
- It says those APIs are Pixel-exclusive now and will reach AOSP and other manufacturers through Android 17 QPR2 in December 2026
- It says the September 2026 Pixel Update Bulletin carries extra patches to standard Android platform components that were not issued through the September 2026 Android Security Bulletin or through preview patches
- GrapheneOS says other Android makers will not get those patches until December 2026, and that it can ship them early by reverse engineering the code
- It says its own port to Android 17 QPR1 was finished before the 15 September release but that it does not have permission to ship it yet
- It says a source-code request made on 1 September was only fulfilled on 16 September, and that Pixels are now harder to support than many other devices