GrapheneOS developers attempted a partial port to the Pixel 11 series but found it impossible to complete because ARM hardware memory tagging (MTE) is not supported in the device's software, firmware and likely hardware. MTE is a core defense used across GrapheneOS - including kernel and standard system processes - to mitigate remote and many local memory-corruption exploits. While Pixel 8 introduced hardware MTE and Android 16’s Advanced Protection Mode enables it for a few processes, GrapheneOS enables MTE much more broadly and offers per-app controls; Apple’s iPhone 17 provides a similar always-on Memory Integrity Enforcement. The lack of exposed MTE on Pixel 11 prevents GrapheneOS from meeting its security baseline.
The Pixel 11 does add features such as ML‑DSA post‑quantum verified boot, an AOSP IMS replacement for Samsung Shannon IMS, and Titan M3 for better Before‑First‑Unlock protection, but losing MTE severely weakens After‑First‑Unlock security. Performance and value are also questioned: modest CPU gains, underpowered GPU, and reduced RAM make it an incremental, expensive upgrade. GrapheneOS recommends against buying Pixel 11 for users seeking its hardened OS, is considering skipping Pixel 11 support in favor of Motorola devices that include MTE, and forum responses reflect debate - some urge maintaining Pixel support, while others insist MTE must remain a minimum requirement.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.