The update Android 17 QPR1, released by Google as September’s Pixel Drop, is stirring quite a controversy. While Pixel smartphone owners benefit from new features, the GrapheneOS makes strong accusations against the Mountain View company.
At the center of the controversy is the alleged intention of the American brand to withhold for itself, and for its devices, the most recent APIs and, an even more critical aspect, important security patches, denying them to other manufacturers and to projects based on AOSP (Android Open Source Project).
GrapheneOS, through a series of statements released after the debut of QPR1, highlighted a suspected anomalous change in Google’s policy.
According to the developers, Android 17 QPR1 represents the first version since Android 3.x Honeycomb to introduce new APIs for developers without making them simultaneously available through the AOSP channel.
Although the Android developer documentation does attest to the existence of API-level differences between the base Android 17 version and the newer QPR1, and although Google in the past has provided QPR1 GSI (Generic System Image) builds describing them as derived from the same AOSP and GMS sources as the Pixel, the reality for independent projects seems to be different.
GrapheneOS says it has completed porting its code to Android 17 QPR1 even before the official release on September 15, but has not yet obtained authorization to publish.
The team is thus forced to work on backporting the firmware, the kernel drivers, the userspace drivers, and the Pixel HALs from QPR1 to the base Android 17 version.
The most alarming aspect of GrapheneOS’s complaint concerns the handling of security patches. The analysis of Pixel’s September 2026 update bulletin reveals the presence of additional security fixes compared to those listed in the standard Android bulletin for the same month. This confirms that Pixel devices benefited from a higher level of protection.
The problem arises because, according to GrapheneOS, some of these vulnerabilities affect standard Android platform components, used also by devices not branded by Google.
These fixes, the project claims, were not included in the standard September security bulletin, nor were they provided as early patches to other OEMs.
GrapheneOS harshly criticizes this conduct, stating that Google should not block access to security patches relating to the standard Android code from other manufacturers.
According to the project’s estimates, other OEMs will receive these crucial fixes only in December, in conjunction with the release of Android 17 QPR2, leaving their users exposed for months to known vulnerabilities.
The disparity in early access to features, bug fixes, and, above all, critical security patches raises legitimate questions about a potential unfair competitive advantage granted to Pixel devices over the competition.
GrapheneOS notes that this fragmentation makes support for Pixels more complex than for other smartphones, while recognizing the importance of Pixels for the project thanks to their distinctive update and security characteristics.
To address these challenges, GrapheneOS eyes a future partnership with Motorola with interest. This collaboration, according to the team, could greatly simplify support for future devices, ensuring direct access to official firmware and driver source code, thus bypassing the limitations imposed by Google’s current management of the AOSP project.
Google has announced the introduction of Home MCP, an interface based on the Model Context…
A few days after the public release of the new iOS 27, users have already…
The launch of iPhone Duo, instead of pushing customers toward the new Apple device, seems…
iQOO confirmed with an official teaser that Pad Ultra will debut on September 29, presenting…
OPPO has confirmed the specifications of Watch S2 just days before the official debut, set…
OpenAI has announced the withdrawal of GPT-5.5 starting from October 14, across ChatGPT, Work and…