GrapheneOS Says Pixel 11 Lacks Memory Tagging and Advises Against Buying It
Security / news
GrapheneOS Says Pixel 11 Lacks Memory Tagging and Advises Against Buying It
The hardening-focused Android project has stopped a Pixel 11 port after a week because ARM's Memory Tagging Extension is missing. Google has not confirmed whether the chip has it.

GrapheneOS says it cannot finish a port to Google's Pixel 11 because the phones lack ARM's Memory Tagging Extension (MTE), the hardware check that catches a memory-corruption exploit after an attacker has already found a bug. The project "strongly recommend[s] against buying Pixel 11 devices", per Android Authority, and points buyers to the Pixel 8, 9 and 10.
Google has not confirmed whether Pixel 11 supports MTE. Everything below is GrapheneOS's claim, relayed by outlets, and the project itself says the absence in hardware is "near certain" rather than proven.
What GrapheneOS actually said
The quote at the centre of the story is: "We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware." CyberInsider reports the conclusion came after a week of porting work.
Tech Times dates the announcement to August 29 and says the chip is the Tensor G6. That article goes further than the project did, claiming Google removed MTE from the die. Treat that as an inference: GrapheneOS names cost-cutting as the most likely reason and concedes an undisclosed hardware flaw is possible.
Why MTE matters on a phone
MTE tags memory allocations and checks the tag on every access, so a use-after-free or buffer overflow trips a fault instead of running. GrapheneOS has used it across the base OS since the Pixel 8 in October 2023, with per-app toggles for incompatible applications.
How common are such bugs? The sources disagree: Android Authority repeats a Google figure of over 60% of high-severity bugs, while Tech Times says roughly 76% of Android flaws. They measure different things, so neither should be read as a precise rate.
| Phone | GrapheneOS position |
|---|---|
| Pixel 8, 9, 10 | Supported, with MTE |
| Pixel 11 | Port stopped, MTE missing |
| Pixel 11a (rumoured) | Developers hopeful, per Android Authority |
| Motorola flagship, 2027 | Planned partnership, MTE support expected |
The preconditions for the risk
The lost protection applies when a phone is already unlocked and running an app or process with a memory bug. Stock Pixel 11 buyers lose a layer, not the whole stack, and Google has not said what stock Android on Pixel 11 does about MTE.
For GrapheneOS users the cost is concrete. Tech Times says Pixel 8, 9 and 10 stay supported through 2030 to 2032, so nobody on those phones loses anything today.
Where this leaves buyers
CyberInsider adds that the team had heard from a Google insider that MTE could be dropped from a future Pixel generation, and that GrapheneOS suggests returning a Pixel 11 if possible. Tech Times notes Apple made Memory Integrity Enforcement standard across the iPhone 17 line at the same time.
If you need GrapheneOS, buy a Pixel 10 or earlier. If you do not, wait for Google to say what Tensor G6 contains. Android Authority says the developers may shift their effort to Motorola, with a flagship expected in 2027.
It is a different kind of hardware-lifetime argument from the one in Valve's old AMD GPU driver work, and Google's disclosure habits are the subject of our look at its data centre redaction. The next milestone is a Google statement, which nobody has dated.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.