Search results for

All search results
Best daily deals

Affiliate links on Android Authority may earn us a commission. Learn more.

GrapheneOS accuses Google of gatekeeping Android 17 features and security fixes

The platform has raised concerns over Pixel-exclusive Android 17 APIs and security patches.
By

Sep 16, 2026 — 11:29 PM ET

grapheneos boot animation
Calvin Wankhede / Android Authority
Add Android Authority on Google:
TL;DR
  • Google has released Android 17 QPR1 as part of the September Pixel Drop, but GrapheneOS says the update contains APIs and other changes that aren’t being made available to the wider Android ecosystem at the same time.
  • GrapheneOS also claims Google is withholding some security fixes for standard Android components from other OEMs until Android 17 QPR2 arrives in December.

Google has released the stable Android 17 QPR1 update as part of the September Pixel Drop. While the new software brings a range of features and changes to supported Pixel phones, folks over at GrapheneOS are accusing Google of gatekeeping some of the latest Android features and security fixes from other Android manufacturers and AOSP-based projects.

In a series of posts following the QPR1 release, GrapheneOS highlighted what it says is an unusual change to how Google is handling Android’s APIs.

According to the project, Android 17 QPR1 is the first Android release since the Android Honeycomb era to introduce new developer APIs without making them available through the Android Open Source Project (AOSP).

GrapheneOS Android 17 QPR1 1
GrapheneOS/matodon

The Android developer documentation does show API differences between Android 17 and Android 17 QPR1. Google also previously provided QPR1 GSI builds to developers, describing them as being built from the same AOSP and GMS sources as the corresponding Pixel builds.

However, GrapheneOS argues that the situation is different for projects that are trying to ship their own Android-based operating systems.

“We already ported our code to Android 17 QPR1 since before it was released on September 15th, but don’t have permission to release it yet,” the project said. It added that it is currently working on backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 to Android 17 instead.

Moreover, GrapheneOS is also pointing fingers at how Google is handling some security patches.

GrapheneOS Android 17 QPR1 2
GrapheneOS/matodon

The project’s posts point to the September 2026 Pixel Update Bulletin, which contains additional security fixes beyond those listed in the standard September Android Security Bulletin. Google’s Pixel bulletin confirms that Pixel devices received patches for additional vulnerabilities.

GrapheneOS says some of these patches affect standard Android platform components used by non-Pixel devices as well. It claims those fixes have not been made available through the September Android Security Bulletin or preview patches for other OEMs.

“Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs, but that’s what they’ve started doing,” GrapheneOS said. The project claims other OEMs will receive those patches in December with Android 17 QPR2.

GrapheneOS also questioned whether giving Pixel devices early access to Android features, bug fixes, and certain security patches gives Google’s phones an advantage over devices from other Android manufacturers.

“Pixels are now significantly harder to support than many other devices,” GrapheneOS said, while acknowledging that Pixels remain useful for the project because of their update and security features.

The project also says its upcoming Motorola partnership could make supporting future devices easier because it will receive official firmware and driver code directly.

Follow

Thank you for being part of our community. Read our Comment Policy before posting.