(There are probably even more by now anyway)
This doesn’t include any of the CVEs from GrapheneOS itself, and those exist as well.
Then the GrapheneOS team is explicitly developing for Google hardware or smartphones with closed-source software from Qualcomm—where they have absolutely no access, can’t fix anything at all, etc.
They’re explicitly choosing hardware we can't trust.
Since the brainwashed GrapheneOS cult followers just blindly dismiss any criticism anyway, I'm not even going to bother anymore here in the community. You guys won't accept it either way. True to the motto "Hail GrapheneOS"
You blindly trust the underlying hardware, which has its own real-time operating system (RTOS). There's no point in arguing with you about this.
The better alternative? Don't trust any hardware where the software and hardware aren't 100% open. You simply can't trust anything else at all. Hard to understand, isn't it?
I don't feel like arguing with the grapheneOS cult either, because it's pointless. Stay in your bubble.
Project Ara would have been an alternative at one time... That's why Google bought it and put it on hold.
Then there’s the ultimate argument that applies to everything that uses cellular networks... the SS7 protocol
Class 1 (normal SMS)
CLASS 0 (flash SMS)
TYPE 0/Stealth Ping <
( • Technical identifier: The TP-PID byte is set exactly to 0x40 (Short Message Type 0).
• Protocol behavior: When this SMS reaches the phone, the baseband (the Qualcomm/Samsung modem chip) reads the header. The standard mandates the following for Type 0: “The device must acknowledge receipt of the message but must neither display the content nor store it in memory.”
• The effect: The cell phone receives the SMS. The display remains black, no sound is heard, and the GrapheneOS interface is completely unaware of it. However, the modem chip automatically sends an acknowledgment (ACK) back to the sender via the SS7 network.
This cannot be blocked by the GrapheneOS team, etc.
Oh, right—encryption in mobile communications itself ends as soon as the connection switches from a cell tower to satellite communication. In other words, the connection goes from cell phone < encrypted > to cell tower < unencrypted > to satellite. ( https://youtu.be/fM5w7bFNvWI ) However, this applies only to the encryption of the cellular network itself.
GrapheneOS may be the best, but you should treat it as untrustworthy.
BTW, I use Chinese stuff. They're more interested in state secrets and such, and less in my religion, sexual orientation, etc.—the kinds of things the West is increasingly using against its own citizens... I wonder why that Chinese stuff was banned in the U.S.... Yeah, I wonder why...
But you could also, for example, use a Fairphone and remove certain modules yourself.
Keep your cynical sarcasm and keep deluding yourself that grapheneOS is the secure OS, even though it runs exclusively on that specific hardware.
Like I said, I’m not interested in the cult—just stay in your bubble.
If you say "GrapheneOS may be the best, but you should treat it as untrustworthy.", is it fair to single it out as the "BackdoorOS"? It seems more like your position is that no closed source hatdware can be trusted? On that level we also can't trust any software because of Ken Thompsons "Reflections on trusting trust". So is your point that phones/computers can't be trusted in general, or that GrapheneOS is especially unsafe compared to available alternatives?
In the long run, I’m pinning my hopes on the LibrePhone project, which is reverse-engineering firmware blobs to eventually offer open-source alternatives. I hope to be able to combine that with the Fairphone at some point (which, as I mentioned, already allows you to remove modules like the microphone, camera, etc.).
But right now, there simply isn’t any alternative free, open-source firmware yet. So, yes, it’s the best option for now—though it’s still not trustworthy. Especially since old cross-device tracking methods, such as uXDT, continue to play a role there as well.
With PCs and laptops, there isn’t anything completely open-source either, but it’s still easier to run them in a completely isolated environment, because a smartphone that’s completely isolated loses its purpose—that’s the difference.
GrapheneOS
Alias BackdoorOS
Source?
Just a small sample Qualcomm CVEs – August 2026
Additional Qualcomm CVEs Affecting Snapdragon
(There are probably even more by now anyway) This doesn’t include any of the CVEs from GrapheneOS itself, and those exist as well. Then the GrapheneOS team is explicitly developing for Google hardware or smartphones with closed-source software from Qualcomm—where they have absolutely no access, can’t fix anything at all, etc. They’re explicitly choosing hardware we can't trust.
Since the brainwashed GrapheneOS cult followers just blindly dismiss any criticism anyway, I'm not even going to bother anymore here in the community. You guys won't accept it either way. True to the motto "Hail GrapheneOS"
You blindly trust the underlying hardware, which has its own real-time operating system (RTOS). There's no point in arguing with you about this.
Ah yes I'm sure there's a better alternative /s
These don't prove your point. They're not backdoors. If they were they would have never Bern assigned a CVE.
The better alternative? Don't trust any hardware where the software and hardware aren't 100% open. You simply can't trust anything else at all. Hard to understand, isn't it?
I don't feel like arguing with the grapheneOS cult either, because it's pointless. Stay in your bubble.
Project Ara would have been an alternative at one time... That's why Google bought it and put it on hold.
Then there’s the ultimate argument that applies to everything that uses cellular networks... the SS7 protocol Class 1 (normal SMS) CLASS 0 (flash SMS) TYPE 0/Stealth Ping <
( • Technical identifier: The TP-PID byte is set exactly to 0x40 (Short Message Type 0). • Protocol behavior: When this SMS reaches the phone, the baseband (the Qualcomm/Samsung modem chip) reads the header. The standard mandates the following for Type 0: “The device must acknowledge receipt of the message but must neither display the content nor store it in memory.” • The effect: The cell phone receives the SMS. The display remains black, no sound is heard, and the GrapheneOS interface is completely unaware of it. However, the modem chip automatically sends an acknowledgment (ACK) back to the sender via the SS7 network. This cannot be blocked by the GrapheneOS team, etc.
Oh, right—encryption in mobile communications itself ends as soon as the connection switches from a cell tower to satellite communication. In other words, the connection goes from cell phone < encrypted > to cell tower < unencrypted > to satellite. ( https://youtu.be/fM5w7bFNvWI ) However, this applies only to the encryption of the cellular network itself.
GrapheneOS may be the best, but you should treat it as untrustworthy.
BTW, I use Chinese stuff. They're more interested in state secrets and such, and less in my religion, sexual orientation, etc.—the kinds of things the West is increasingly using against its own citizens... I wonder why that Chinese stuff was banned in the U.S.... Yeah, I wonder why...
But you could also, for example, use a Fairphone and remove certain modules yourself.
This is why I just yell everything out the window like a truly rational person
Keep your cynical sarcasm and keep deluding yourself that grapheneOS is the secure OS, even though it runs exclusively on that specific hardware. Like I said, I’m not interested in the cult—just stay in your bubble.
If you say "GrapheneOS may be the best, but you should treat it as untrustworthy.", is it fair to single it out as the "BackdoorOS"? It seems more like your position is that no closed source hatdware can be trusted? On that level we also can't trust any software because of Ken Thompsons "Reflections on trusting trust". So is your point that phones/computers can't be trusted in general, or that GrapheneOS is especially unsafe compared to available alternatives?
In the long run, I’m pinning my hopes on the LibrePhone project, which is reverse-engineering firmware blobs to eventually offer open-source alternatives. I hope to be able to combine that with the Fairphone at some point (which, as I mentioned, already allows you to remove modules like the microphone, camera, etc.). But right now, there simply isn’t any alternative free, open-source firmware yet. So, yes, it’s the best option for now—though it’s still not trustworthy. Especially since old cross-device tracking methods, such as uXDT, continue to play a role there as well.
With PCs and laptops, there isn’t anything completely open-source either, but it’s still easier to run them in a completely isolated environment, because a smartphone that’s completely isolated loses its purpose—that’s the difference.
Why would they use closed source Qualcomm blobs? Are there no Qualcomm modules in the phone?
Because the Firmware etc is only closed source xD Qualcom is not a good guy/company Google is not a good company..