Google made Pixel 11 unsafe to save a few bucks

Security researchers have advised buyers to skip the Pixel 11.

pixel 11 hardware memory tagging MTE GrapheneOS
The Pixel 11 might have taken a step back, but at least Google's margins didn't. | Image by PhoneArena
0
For those who think standard Android isn't secure enough, GrapheneOS is a solid alternative. Built on the Android Open Source Project (AOSP), this privacy-focused OS makes it harder for cybercriminals to exploit code vulnerabilities. It officially supports the Pixel 6 through Pixel 10a, but the new Pixel 11 is missing out because Google has removed hardware memory tagging support. 

Even if you aren't interested in GrapheneOS, the omission makes the Pixel 11's security inherently weaker.

Cost savings over security



When attempting to make GrapheneOS work on the Pixel 11, the developers found that it doesn't support ARM hardware memory tagging (MTE). MTE detects programming mistakes that can lead to security exploits.

Google appears to have dropped support to save money, because apparently, reduced RAM, a kneecapped processor, and a struggling GPU weren't enough compromises.

GrapheneOS uses MTE throughout the operating system, including the kernel, which is the core of the OS. It protects against almost all attacks involving memory management vulnerabilities.

How does this make you feel about the Pixel 11?
24 Votes

A downgrade


Even on MTE-capable Android phones, the capability wasn't used broadly. In contrast, Apple's Memory Integrity Enforcement (MIE) is always enabled on the iPhone 17. However, even Apple didn't enable MTE as aggressively as GrapheneOS did and left out third-party apps due to stability concerns.

Recommended For You
The Pixel 11 comes with notable security improvements. It uses the post-quantum cryptographic ML-DSA algorithm, has moved to the AOSP IMS framework from the proprietary Samsung Shannon IMS software, and features the latest Titan M3 security chip.

However, those upgrades don't make up for the loss of MTE. The GrapheneOS developers went so far as to caution against buying the Pixel 11. They have their reasons. For instance, while Titan M3 makes it harder for someone in physical possession of the Pixel 11 to break into it, it may not defend as well against malicious websites and apps.

Those looking for a secure Android flagship are being advised by the GrapheneOS team to wait for upcoming Motorola hardware.

Why MTE matters


According to Google's own research, bugs related to how memory is handled are the biggest contributors to security vulnerabilities. MTE is a foundational technology that mitigates risk.

Apple has called it the 'most significant upgrade to memory safety in the history of consumer operating systems.'

You will be fine


Even on the iPhone, third-party apps aren't protected by MTE, and all hell hasn't broken loose. However, for customers who explicitly chose Pixel phones to have peace of mind, the Pixel 11 isn't an option.

Six-month unlimited plan is now 57% off
$90
$210
$120 off (57%)
Mint Mobile is now allowing you to get whichever plan you like for either three, six, or 12 months for just $15/mo. If you go for the six-month unlimited service, for instance, you'll now have to pay just $90 upfront instead of $210.
Buy at Mint Mobile
PhoneArena Recommends
COMMENTS (0)