Google’s September 2026 Pixel Update Bulletin has introduced a series of patches that extend beyond the usual scope of the monthly Android Security Bulletin. Notably, GrapheneOS has pointed out that some of these additional patches affect standard Android platform code, which is applicable not only to Pixel devices but also to non-Pixel hardware. This situation raises concerns, as this platform-level code has not been included in the regular monthly bulletin or the private preview patches that other manufacturers typically utilize to prepare their own updates. As it stands, these updates are unlikely to reach non-Pixel OEMs until the anticipated Android 17 QPR2 release in December.
The complaints
GrapheneOS has highlighted that Android 17 QPR1 introduced new developer APIs that have not made their way into the Android Open Source Project (AOSP), a situation that they assert has not occurred since the days of Android Honeycomb. Their API diff report corroborates this claim, revealing the introduction of one new package, android.hardware.hid, alongside modifications across sixteen others, including android.media, android.os, android.provider, android.telecom, and android.view. Despite GrapheneOS managing to port its code to QPR1 prior to its official release, they still lack the necessary permissions to distribute this work. Currently, the project is backporting Pixel firmware, kernel drivers, userspace drivers, and Hardware Abstraction Layers (HALs) from QPR1 onto Android 17.
Additionally, a compliance issue has emerged, with Google exhibiting delays in adhering to a GPL source request. GrapheneOS requested the sources for a specific build (CD1A.260905.001.A1) on September 1, but access was only granted over two weeks later.
Why this is worrying
While none of these three issues is catastrophic on its own—a three-month patch delay, a halted API rollout, and a two-week wait for source code—collectively, they suggest a troubling pattern. Google appears to be restricting security fixes from the broader Android ecosystem, withholding new APIs from AOSP for the first time in over a decade, and dragging its feet on GPL compliance obligations.
Moreover, the implications for the Android app ecosystem are significant. Google is poised to mandate that every Android app developer, regardless of their platform—be it the Play Store, F-Droid, or elsewhere—register with them. Starting in 2027, this will entail providing legal identification and signing key evidence before any app can operate on certified devices. The process of sideloading an unverified app will become cumbersome, requiring developers to enable developer settings, endure a mandatory 24-hour cooldown, and navigate through multiple warning screens—a tactic reminiscent of classic scare tactics.
GrapheneOS is among numerous organizations advocating for the Keep Android Open campaign in opposition to these developments, joining forces with F-Droid, the Electronic Frontier Foundation, and the Free Software Foundation. This trend reflects a broader strategy by the tech giant to tighten control over access, potentially stifling competition in the process.