GrapheneOS developers announced they cannot complete a port of their security-focused OS to Google’s Pixel 11 series due to the absence of ARM hardware memory tagging (MTE) support.
![]()
According to the GrapheneOS discussion forum, the team completed a partial port after a week of work but was unable to finish it because Pixel 11 lacks support for MTE in software, firmware, and likely hardware. “It appears Google cut an important security feature to save money,” the developers stated.
MTE is a critical security component in GrapheneOS, used across the entire base OS including the kernel and standard base OS processes. According to the developers, it “greatly improves protection against nearly all remote exploits and many local exploits.” Pixel 8 launched with hardware MTE support in October 2023, and GrapheneOS integrated it into their hardened_malloc project and began using it across the OS that same month.
The developers compared Pixel 11’s approach unfavorably to Apple’s implementation. Apple’s Memory Integrity Enforcement (MIE) on iPhone 17 is described as “a high quality implementation of MTE using the latest standard extensions,” with MTE enabled in the kernel and a large portion of the user base.
Pixel 11 does include some security improvements, the developers acknowledged. These include moving to post-quantum secure verified boot using ML-DSA and replacing Samsung Shannon IMS with AOSP IMS. The Titan M3 security chip “should significantly improve protection against data extraction in Before First Unlock state.”
However, the developers said these improvements are undermined by the removal of MTE. They characterized Pixel 11 as overpriced with only incremental CPU improvements, the same GPU, and reduced RAM in base Pro models.
The developers strongly recommend against purchasing Pixel 11 devices, stating that Pixel 8, 9, and 10 have “much better overall security for GrapheneOS.” They noted that Pixel 10 is cheaper with similar hardware and includes MTE.
GrapheneOS has not yet decided whether to support Pixel 11. “It may be best for us to skip the Pixel 11 series devices,” the developers wrote, indicating they may shift focus entirely to upcoming Motorola devices with Snapdragon 8 Elite Gen 5 processors that include MTE support.
Key facts
- GrapheneOS could not complete a Pixel 11 port due to lack of ARM hardware memory tagging (MTE) support
- MTE protects against nearly all remote exploits and many local exploits according to GrapheneOS
- Pixel 8 launched with hardware MTE in October 2023, but Pixel 11 lacks it
- Apple’s iPhone 17 uses Memory Integrity Enforcement, described as a high-quality MTE implementation
- Pixel 11 includes post-quantum secure verified boot and Titan M3, but GrapheneOS says losing MTE undermines AFU security
- GrapheneOS recommends Pixel 8, 9, or 10 over Pixel 11 for security
- GrapheneOS may skip Pixel 11 entirely and focus on upcoming Motorola devices instead