GrapheneOS: Pixel 11 drops ARM memory tagging, blocking full port
Original source
GrapheneOS project: pixel 11 no longer supports hardware memory tagging (MTE)
Hacker News →GrapheneOS says it managed only a partial port to Google’s new Pixel 11 series after a week of effort, and cannot finish because the phones lack support for ARM’s hardware Memory Tagging Extension (MTE) across software, firmware, and—by the project’s assessment—the silicon itself. MTE is a memory-safety feature that tags memory allocations to catch use-after-free and buffer-overflow bugs at runtime, a major class of exploitable vulnerabilities. GrapheneOS has leaned on it heavily as a hardening measure, so its absence removes a meaningful defensive layer on the device.
The project attributes the omission to Google cutting the feature to reduce costs, though that framing is GrapheneOS’s own interpretation rather than a confirmed decision from Google. Earlier Pixels shipped MTE and helped make the line a favored target for security-focused Android builds; losing it on the flagship would mark a notable regression for that audience.
If accurate, the change matters beyond GrapheneOS: MTE is one of the more promising mitigations for the memory-corruption bugs that dominate serious mobile exploits, and dropping it in hardware would weaken defenses for all Pixel 11 users, not just those running custom ROMs. The situation is still developing, and a definitive account will depend on Google clarifying the chip’s actual capabilities.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.