Leaked screenshots and a screen recording from a Chromium Issue Tracker bug report revealed an early look at Google’s internal “Aluminum OS” (ALOS) project—an apparent desktop-oriented Android build tied to Google’s long-running effort to consolidate Android and ChromeOS into a single platform. The report was subsequently made private, but not before the media captured the visuals, which are described as the first “official” visual evidence of the desktop Android interface.
The leak indicates the build ZL1A.260119.001.A1 running on an HP Elite Dragonfly/HP Chromebook-class device using an Intel 12th-gen (Alder Lake-U) x86 processor, suggesting testing on existing Chromebook hardware. Visible UI changes include a desktop-style bar optimized for larger screens (with time/date placement changes), desktop multitasking (side-by-side), and Chrome with extension support; one account also notes prominent Gemini and screen-recording icons, implying potential “AI-native” integration. Overall, the material points to a ChromeOS successor or alternative desktop experience built on Android rather than a conventional ChromeOS evolution.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Coverage of the leak described a desktop-optimized Android interface with a persistent status bar, split-screen multitasking, ChromeOS-like window controls, and an Extensions button in Chrome. The underlying bug report was later restricted or made private after the screenshots and related media were noticed.
A Chromium Issue Tracker bug report inadvertently exposed screenshots and details of Google's in-development desktop-oriented Android environment, including references to the codename ALOS/Aluminum OS. The leak showed the software running on an HP Elite Dragonfly Chromebook with an Android 16-based build.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcetomshardware.com
Open sourcesecurityonline.info
Open source9to5google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.