GrapheneOS says Google is sitting on security patches and new Android 17 APIs that non-Pixel phones should already have. The privacy-focused Android fork laid out its case in a long Mastodon thread on September 16. The timeline it describes would leave every other Android OEM waiting until December for fixes Pixel owners already got this month.
What GrapheneOS says is happening
Android 17 QPR1 shipped as the stable September Pixel Drop on September 15. According to GrapheneOS, that release’s Pixel Update Bulletin contains patches to standard Android platform components, the kind of code every OEM ships, not just Google. GrapheneOS says those same patches have not appeared in the general September 2026 Android Security Bulletin or in any preview patch other manufacturers can pull from.

GrapheneOS also says Android 17 QPR1 introduced new platform APIs that developers can use today only on Pixel hardware. Per GrapheneOS, both the withheld patches and the withheld APIs will not reach the Android Open Source Project or other OEMs until Android 17 QPR2 ships in December 2026.
“Google should not be gatekeeping security patches to the standard Android platform code from Android OEMs but that’s what they’ve started doing. Other OEMs will get these patches in December 2026 via Android 17 QPR2. We can ship them early by reverse engineering the code instead.” — GrapheneOS
GrapheneOS frames this as a structural problem, not a one-off delay. Since Android 16, Google has stopped releasing the QPR1 and QPR3 quarterly builds to AOSP at all, keeping them Pixel-exclusive. Android 17 QPR1 is, by GrapheneOS’s account, the first of those Pixel-only releases to also carry new developer-facing APIs. That is why the gap is visible this month.
Why this matters if you don’t own a Pixel
The practical effect, as GrapheneOS describes it, is simple. A Samsung, Motorola, or any other Android phone will not receive September’s platform-level security fixes through official channels for roughly three more months. GrapheneOS says it can close part of that gap itself, by reverse engineering the missing code for its own supported devices. That workaround does not help the millions of people running stock software from other OEMs.
GrapheneOS also raised a separate complaint about Google’s own compliance. It says it requested source code for a specific Pixel build under Google’s GPL obligations on September 1, and was not granted access until September 16, more than two weeks later. Separately, GrapheneOS argued that giving Pixel devices months of early access to features and security fixes hands Google’s own hardware a competitive edge over the OEM partners it is supposed to be supporting equally.
As of September 17, Google has not publicly responded to these claims. Everything above is GrapheneOS’s own account of what it observed, not an independently audited timeline. No other Android OEM has commented on whether it separately requested these patches or received a different answer.
The pattern behind it
GrapheneOS’s own read is that Google is not doing this to punish rivals. It is protecting Pixel’s edge as the reference Android device. That distinction may be true, and it can still leave every non-Pixel owner in the same position: running an Android version with a documented, months-long patch gap that Google itself created by pulling QPR1 and QPR3 out of AOSP. If you buy a phone specifically because it promises fast security updates, remember this the next time an OEM’s marketing leans on “same day as Pixel.”
Source: GrapheneOS (@GrapheneOS)




