Google’s September 2026 Pixel Update Bulletin contains patches beyond what’s in that month’s regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.
None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.
And at this rate, these won’t reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.
The project is characterizing this as Google “gatekeeping security patches to the standard Android platform code from Android OEMs.” The complaints
GrapheneOS says Android 17 QPR1 shipped new developer APIs that never made it into AOSP. This is something they claim hasn’t happened since Android’s Honeycomb days.
Google’s API diff report backs this up. Comparing Android 17 to QPR1 shows one new package, android.hardware.hid, plus changes across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view.
GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn’t have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.
On top of all that, there’s a compliance issue that seems to be recurring.
Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (CD1A.260905.001.A1) on September 1, and access only came through more than two weeks later.
Why this is worrying
None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code—each is the kind of thing that could pass as a one-off.
Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking GPL compliance it’s required to meet.
Don’t even get me started on what they are doing to the Android app ecosystem.
Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.
Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (classic scare tactics, btw).
GrapheneOS is one of dozens of organizations that signed onto the Keep Android Open campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.
If you ask me, this Big Tech company is doing what’s regrettably natural for it, clamping down open access to things so that its competition cannot benefit.
We need Proper Linux/BSD phone
SailfishOS phone ?
Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.
When is some country’s government finally going to grow a pair and block this shit on the grounds of antitrust law?
Only when they stop getting some kind of benefit from it.
Don’t forget everyone! Cheering on Motorola is no good feat. When the Flock cameras are getting take down. Guess who’s placing new cameras in the exact same places as the Flock poles. Axon and Motorola. Still want your Graphene phone on Motorola? Not a good sign.
It’s called installing apps, not “sideloading”. Installing your programmes into a device you own is normal, being blocked from doing that is abnormal.
I’ve been trying to convince people for the last 10-15 years that Google is no friend to the open source community. It’s been difficult and sounds self-serving as I do it from Apple devices and make no attempt to hide or conceal that.
AOSP and chromium are open source projects. What Google actually puts out — Android and Chrome — are not. They take the open source foundations, and they build upon them with closed-source components. They’ve always done this. AOSP does not have any Google apps either (sometimes called GApps) as those are not open source. Browser and Mail are not Chrome and Gmail, though the former may be a chromium-based browser and the latter may be capable of retrieving and sending through Gmail (much like Apple’s mail app can).
Android is not an open source ally, and macOS is kinda, sorta, not really based on UNIX. But we could flip the script and say that Apple is a friend to open source because macOS is basically UNIX (via OS X and NextStep), while Android isn’t open source at all. I can already see the pitchforks being sharpened. Both positives are technically true from a certain point of view (like Vader having killed Anakin Skywalker, to use Obi-Wan’s example for this turn of a phrase), but the negatives of both are more accurate. Because to really be a friend to the world of open source (and FOSS, and the more preferred licenses), you can’t just half-ass it, you gotta go all the way. Apple isn’t there and neither is Google.
F-Droid is what the Android Market (I’m that old, and older) should have become, with Google offering a repository you can add to F-Droid. Google Play Store is trash and pretty much always has been, and I say that as someone who deals with the App Store (which is also trash) every day.
Of course I also root for GrapheneOS, up until they say you can only use their OS with a Pixel phone. If I want iPhone 11 performance, I’m not spending iPhone 18 Pro money on a Pixel 11, I’m gonna either get iPhone 18 Pro performance, or, if I want Android, I’m looking at the Galaxy S line. I’m not even looking at Pixel and its sorry ass, seven generations behind Tensor line. Bad enough Snapdragon struggles to keep up with Apple silicon. Does Tensor even try?
But nah, I wanna see GrapheneOS do what Andy Rubin did. Make Linux run on phones. But make it run on any phone. I guess I don’t mean “including the iPhone.” That would be nice, but Apple isn’t unlocking that bootloader. But we should expect a free, open source alternative to Android to run on any hardware, not just the one run by the one causing the problems. (So what standards do I aspire my iPhone to? I want it to be more like the Mac, with a terminal and ability to install apps from anywhere.)
If we assume Google is a wiggledog of alphabet (lel) agencies, it would want to wiggle off all deviants and provide a single platform one can exploit in a predictable way and not others. In a subscription-model fashion, they benefit from having an ever moving window of vulnerabilities so their clients need to get the latest ones or otherwise they wouldn’t work. I slightly remember an article concerning russian cops using old Pegasus to dig into someone’s iphone and israelis commenting that it is outdated by a couple of years and is not applicable to modern models.
Privacy-focused OSes and apps out of their control introduce deviances Google doesn’t want to account for, so they establish a total monopoly.
There should be something more than we have now to tell Google should cool the fuck down.
Steam lepton is interesting.
It’s almost like steam is also possibly going after the play store eventually too. So, if they do that, and manufacturers change away, it’s a win








