116

Google's September 2026 Pixel Update Bulletin contains patches beyond what's in that month's regular Android Security Bulletin. According to GrapheneOS, some of those extra patches touch standard Android platform code, the kind that runs on non-Pixel devices, not just Pixel-branded hardware.

None of that platform-level code has reached the regular monthly bulletin or the private preview patches other manufacturers typically draw from to get their own patches ready.

And at this rate, these won't reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.

The project is characterizing this as Google "gatekeeping security patches to the standard Android platform code from Android OEMs." The complaints

GrapheneOS says Android 17 QPR1 shipped new developer APIs that never made it into AOSP. This is something they claim hasn't happened since Android's Honeycomb days.

Google's API diff report backs this up. Comparing Android 17 to QPR1 shows one new package, android.hardware.hid, plus changes across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view.

GrapheneOS has ported its code to QPR1 before Google even released it, but still doesn't have permission to ship that work. For now, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and HALs from QPR1 onto Android 17 instead.

On top of all that, there's a compliance issue that seems to be recurring.

Google was slow to comply with a GPL source request. GrapheneOS requested sources for a build (CD1A.260905.001.A1) on September 1, and access only came through more than two weeks later.

Why this is worrying

None of these three issues is catastrophic by itself. A three-month patch delay, a paused API rollout, a two-week wait on source code—each is the kind of thing that could pass as a one-off.

Taken together, however, they point to a recurring theme. Google is holding security fixes back from the wider Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and slow-walking GPL compliance it's required to meet.

Don't even get me started on what they are doing to the Android app ecosystem.

Google is on track to require every Android app developer, whether on the Play Store, F-Droid, or anywhere else, to register with them. Come 2027, that means handing over legal identification and signing key evidence before an app can run on any certified device.

Sideloading an unverified app following this would mean enabling developer settings, waiting through a mandatory 24-hour cooldown, and clicking past several warning screens (classic scare tactics, btw).

GrapheneOS is one of dozens of organizations that signed onto the Keep Android Open campaign opposing this, alongside F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation.

If you ask me, this Big Tech company is doing what's regrettably natural for it, clamping down open access to things so that its competition cannot benefit.

you are viewing a single comment's thread
view the rest of the comments
[-] onlinepersona@programming.dev 19 points 1 day ago

This will be solved once the Motorola devices are on the market, right? Pixel devices can then be replaced and money can stop going to another US big tech company.

[-] pianoplant@lemmy.world 16 points 1 day ago

Not really. I mean the reliance on pixel hardware will be, but the issue here is that Google provided security fixes to pixels without fixing those same security flaws in AOSP. It's a software thing, not hardware.

[-] Auli@lemmy.ca 1 points 13 hours ago

I thought OEMs got the fixes also.

[-] pianoplant@lemmy.world 2 points 12 hours ago

From the article:

And at this rate, these won't reach non-Pixel OEMs at all until Android 17 QPR2 ships later this year in December.

[-] cm0002@suppo.fi 17 points 1 day ago

Probably, but not just on the market, picked up and sold by the carriers.

Currently Pixels are the only phones where you can unlock the bootloader (ironically) that are also freely purchasable from carriers (which is how most people buy their phones here) in the US

[-] Zangoose@lemmy.world 2 points 13 hours ago

Worth noting that when you buy a pixel from a carrier in the US the bootloader is typically locked anyway, at least for the big ones. This even includes versions where the SIM is unlocked to support other carriers

[-] onlinepersona@programming.dev 14 points 1 day ago

Europe does have more options, luckily.

[-] pumpupthejam@piefed.social 10 points 1 day ago

From a consumers point of view, Europe has more options in pretty much every department (other than firearms obvs).

[-] Viking_Hippie@lemmy.dbzer0.com 9 points 1 day ago

other than firearms obvs

Which is ALSO a good thing, obviously

[-] bombadil@programming.dev -2 points 15 hours ago

Why? Several countries in the European region don't seem to have an issue allowing guns... Switzerland, Italy, Czech, Estonia, Latvia, Lithuania etc.

[-] unglueclass23@programming.dev 1 points 4 hours ago

I'm Lithuanian. It's pretty strict here with guns, really can't compare it with USA and not really sure why you mentioned it.

[-] Safeguard@beehaw.org 6 points 14 hours ago

And those people are trained, checked, registered, need a license retrain every so often, etc, etc..

[-] lemmysmash@beehaw.org 3 points 10 hours ago

Which is ALSO a good thing, obviously :)

[-] bombadil@programming.dev 0 points 8 hours ago

even if that is true (I don't know), I don't think it answers the question of why having guns is inherently a bad thing

[-] Safeguard@beehaw.org 2 points 4 hours ago

It's not. But it's gets harder to control them.

this post was submitted on 20 Sep 2026
116 points (98.3% liked)

Opensource

6740 readers
137 users here now

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

CreditsIcon base by Lorc under CC BY 3.0 with modifications to add a gradient



founded 3 years ago
MODERATORS