GrapheneOS warned users not to buy Google's Pixel 11 for its hardened Android distribution and said it may abandon its incomplete Android 17 port after finding no ARM Memory Tagging Extension (MTE) support in the device's software or firmware. The project believes MTE is also likely absent from the hardware; the feature uses tagged memory allocations to detect invalid accesses and materially complicate exploitation of memory-corruption flaws, including remote and local attacks.
GrapheneOS has used MTE extensively across its base OS, kernel, and standard system processes since the Pixel 8, and considers its removal a significant security regression. While Pixel 11 reportedly adds ML-DSA post-quantum verified boot, AOSP IMS, and improved Titan M3 protections before first unlock, GrapheneOS said these controls do not compensate for missing MTE. It recommends Pixel 8, Pixel 9, or Pixel 10 models for GrapheneOS deployments and may place greater emphasis on future Motorola devices through its partnership.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
GrapheneOS-reported observations indicated that Android 17 QPR2 Beta 4 added Pixel 11 support and firmware changes restoring some MTE support. The reported restoration, its performance implications, and any related hardware or firmware limitations had not been independently confirmed.
GrapheneOS said it may abandon Pixel 11 support and advised prospective GrapheneOS users not to buy the device, or to return it if possible. The project recommended Pixel 8, 9, and 10 models instead, stating Pixel 11's other reported protections do not offset the loss of MTE.
During a partial Android 17-based port to the Pixel 11, GrapheneOS found ARM Memory Tagging Extension support absent from software and firmware and likely unavailable in hardware. It said this prevents completion of the port because MTE underpins protections in its OS, kernel, and standard processes.
GrapheneOS and Motorola announced a partnership to produce high-end Qualcomm-based smartphones, which GrapheneOS expects will provide direct access to components for secure Google-free Android devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcescworld.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.