GrapheneOS may skip Pixel 11 over missing MTE
Original: Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped
Why This Matters
MTE is a rare hardware-level memory safety net; losing it in a flagship signals a real security regression.
GrapheneOS says Pixel 11 lacks ARM Memory Tagging Extension (MTE) support in hardware, firmware, and software—a security feature the project uses OS-wide since October 2023—and recommends against buying the device.
After a week of partial porting work, GrapheneOS announced it may skip official support for the Pixel 11 series because Google appears to have removed ARM hardware Memory Tagging Extension (MTE) support. GrapheneOS uses MTE across the entire OS stack—kernel, base processes, and optionally all user-installed apps—to block the vast majority of remote exploits and many local ones. Pixel 8 launched with MTE in October 2023; GrapheneOS integrated it immediately. By contrast, stock Android only enables it for a handful of processes via Advanced Protection Mode in Android 16.
For context, Apple quietly did the opposite: iPhone 17 ships Memory Integrity Enforcement (MIE), a full MTE implementation enabled by default in the kernel and large portions of userspace. GrapheneOS praised Apple's execution while blasting Google's apparent cost-cutting decision.
Pixel 11 does bring real gains—post-quantum verified boot (ML-DSA), Titan M3 for stronger Before First Unlock protection, and replacing Samsung's Shannon IMS with AOSP IMS. But the project says losing MTE 'craters' After First Unlock security. It also notes that Pixel 11 is more expensive than Pixel 10, offers incremental CPU gains, the same GPU, and reduced RAM on Pro base models. GrapheneOS explicitly recommends Pixel 8, 9, or 10 instead, and is partnering with Motorola—whose upcoming Snapdragon 8 Elite Gen 5 device will include MTE—for its next hardware push.