07.26.25 · The Cape Team

GrapheneOS: Supported Devices, Security Features, and More

If you want to protect and de-Google your smartphone while still enjoying the customizability of Android, GrapheneOS can be a smart choice. The problem is that it’s only available on select devices, so you can’t install it on just any phone.

In this guide, we’ll cover the current lineup of GrapheneOS-supported devices, as well as upcoming additions, to outline your options. You’ll also learn how the OS handles security, privacy, and patches.

Before moving into the specifics, let’s have a closer look at the core idea behind GrapheneOS.

What Is GrapheneOS?

GrapheneOS is an open-source based on Android, more specifically the Android Open Source Project (AOSP), and has a focus on device security and privacy enhancements. It does this by hardening the OS and app sandboxes to mitigate common vulnerabilities associated with Android phones.

Think of GrapheneOS as a fortified Android without pre-installed Google services. You can install a sandboxed Google Play version to download common apps, and they’ll run with much fewer permissions that expand your phone’s attack surface. Alternatively, if you want a fully de-Googled experience, you can use the Aurora Store to access apps.

While some companies offer devices with GrapheneOS pre-installed, the official recommendation is to purchase a compatible phone and install the OS yourself via official channels. The preferred method is the web installer, with support from the available if needed.

GrapheneOS is built on open-source code, which means users can:

  • Access its code publicly
  • Verify all security features independently
  • Make modifications to suit their needs

This kind of transparency alone gives it a . Anyone can audit the code, so there’s a broad community of experts who can identify vulnerabilities and patch them quickly.

GrapheneOS offers plenty of security features you don’t get with Android and follows the latest trends of combining hardware- and software-powered protection. While this strengthens the device’s overall security, it comes at a tradeoff: the OS supports only a limited range of devices.

What Phones Support GrapheneOS?

Historically, GrapheneOS support has been exclusive to Pixel devices, but this is set to change following the recently announced . The OS remains limited to Pixel for now, with support for select Motorola devices .

The following sections provide more details on GrapheneOS device support, focusing on:

  1. GrapheneOS-supported Pixel models
  2. Upcoming support for Motorola devices

1. Pixel Phones With GrapheneOS Support

As of 2026, GrapheneOS is only available on select Pixel phones that meet its established hardware security requirements. This primarily includes the Titan M (or Titan M2) chip, which serves as a root of trust. The chip detects unauthorized access attempts within the device and the OS, and manages core processes, such as:

  • Secure boot
  • Lock screen security
  • Transactions within third-party apps

This doesn’t mean all Pixels with the Titan M chip are compatible with the OS; the phone must also meet other hardware and firmware requirements.

Use the table below to find the series and models that support GrapheneOS*:

Pixel Series

Models (Codename)

Pixel 10**

  • Pixel 10 Pro Fold (rango)
  • Pixel 10 Pro XL (mustang)
  • Pixel 10 Pro (blazer)
  • Pixel 10 (frankel)

Pixel 9

  • Pixel 9a (tegu)
  • Pixel 9 Pro Fold (comet)
  • Pixel 9 Pro XL (komodo)
  • Pixel 9 Pro (caiman)
  • Pixel 9 (tokay)

Pixel 8

  • Pixel 8a (akita)
  • Pixel 8 Pro (husky)
  • Pixel 8 (shiba)

Pixel 7

  • Pixel 7a (lynx)
  • Pixel 7 Pro (cheetah)
  • Pixel 7 (panther)

Pixel 6

  • Pixel 6a (bluejay)
  • Pixel 6 Pro (raven)
  • Pixel 6 (oriole)
1

*Note: Information updated in March 2026.

1

**Although the new Pixel 10a isn’t on the list of supported devices, support for this model for the near future.

GrapheneOS also supports Pixel Fold (felix) and Pixel Tablet (tangorpro), which receive regular updates alongside the supported phones listed above. GrapheneOS announced on its official X account that, in addition to current Pixel models, it , independent of its partnership with Motorola.

Which Pixels No Longer Receive Support?

The following models are end-of-life, so they only receive minimal updates now:

  • Pixel 5a (barbet)
  • Pixel 5 (redfin)
  • Pixel 4a (5G) (bramble)
  • Pixel 4a (sunfish)
  • Pixel 4 XL (coral)
  • Pixel 4 (flame)

Besides device restrictions, your cellular carrier also matters. Some vendors (like Verizon) sell Pixel devices that are carrier-locked, which means . You won’t be able to , as it requires an unlocked bootloader.

While some carriers may remove the hardware restrictions after contractual terms, others may not. That’s why you should make sure the Pixel device is fully unlockable when purchasing from a major carrier.

2. GrapheneOS Support for Future Motorola Releases

was announced at the Mobile World Congress (MWC) on March 2, 2026, officially ending the Pixel-exclusive support streak. While the announcement didn’t include precise timelines, GrapheneOS confirmed on X that support is aimed toward .

Potential Motorola releases with integrated GrapheneOS haven’t been confirmed yet, but users the same way they do on Pixels. The company also noted that Motorola is designing new phones to meet GrapheneOS’s long-term update and hardware security requirements, so current devices may not be eligible.

However, these next-generation Motorola devices known 2026 models, including the Motorola Signature, Motorola Razr Fold, and Motorola Razr Ultra.

The GrapheneOS team added that they , with support potentially expanding to fold-and-flip variants.

Can GrapheneOS Be Installed on Devices Other Than Google Pixel and Motorola?

GrapheneOS currently only works on Pixel devices, with support for select Motorola devices planned for 2027. It cannot be installed on other phones through standard methods like Generic System Images (GSI). As of 2026, there’s no official support or dedicated GrapheneOS builds for any other brands or models, so you’ll need a Pixel or one of the upcoming supported Motorola devices to run it.

This might come as a surprise considering that GrapheneOS is open-source, which means anyone should be able to modify it and adapt it to other devices.

While this is technically possible, most other devices don’t meet the security standards of GrapheneOS. This means that even if you modified the code and installed the OS on an incompatible device, you’d end up with lackluster security due to hardware and software limitations, like:

  • Poorly implemented verified boot
  • A lack of robust, secure elements
  • Infrequent updates

Key GrapheneOS Security Features

If you don’t mind device restrictions and are happy with a Pixel, or are considering one of Motorola’s future releases, you can leverage the many , most notably:

  1. Hardened OS and apps
  2. Hardware-backed protections
  3. Comprehensive privacy permissions
  4. Advanced locking features

You can see a detailed breakdown of the security measures below.

1. Hardened OS and Apps

The main benefit of GrapheneOS is that it hardens Android by mitigating plenty of vulnerabilities through core security upgrades. These upgrades are particularly focused on:

  • Minimizing the attack surface
  • Mitigating exploits
  • Improving app sandboxing
  • Strengthening memory safety

The good news is that GrapheneOS’s security measures are in the backend (for the most part), so your phone will feel like classic Android at first glance. You’ll only need to familiarize yourself with a few new options and toggles for permissions (covered in the following sections).

Besides hardening the system, GrapheneOS comes with several apps that act as secure alternatives to Android’s options or provide additional security layers. Some of the key apps are outlined in the following table:

App

Overview

Vanadium

A hardened variant of Chromium/WebView used for privacy-focused web browsing

Secure camera app

Provides the key features of a stock camera app with security enhancements like stripping EXIF metadata, such as location data, to only include the image’s orientation

Auditor

A hardware-based app used for device attestation to let you verify that your device’s firmware and OS haven’t been tampered with

Combined with the ability to run Google Play services within a standard app sandbox, these security measures minimize data collection and reduce both the common and lesser-known vulnerabilities a hacker might exploit. The result is an OS that feels familiar while actively working in the background to prevent attacks.

2. Hardware-Backed Protections

Beyond software protections, GrapheneOS relies on a set of hardware-backed mechanisms required on every supported device. Core firmware elements are isolated from the main operating system, so that even if the OS is compromised, components such as the bootloader and chipset remain protected.

Each GrapheneOS-supported device includes a Titan M or Titan M2 security chip, which operates independently of the main processor and OS. The chip enforces hardware-verified boot by checking the integrity of the firmware and OS at every startup, providing continuous protection across all layers.

Hardware-backed memory safety is supported by hardened malloc (memory allocator) and hardware memory tagging (MTE). While the memory allocator reduces the time sensitive data spends in memory and helps prevent heap-based attacks, MTE tags memory blocks for early detection of threats such as use-after-free exploits.

3. Comprehensive Privacy Permissions

To minimize unnecessary data collection, Android introduced app-level permissions that let users choose which services each app can access. GrapheneOS takes this feature further by offering additional permission toggles, such as:

  • Network permission toggle: Cuts off both cellular and Wi-Fi access for a given app
  • Sensor permission toggle: Allows users to disable access to motion and environmental device sensors, such as accelerometer, gyroscope, thermometer, and magnetometer
  • Android Auto permission toggles: Let users configure the access of the Android Auto app (downloaded from the sandboxed Google Play)

GrapheneOS also doesn’t grant broad file or contact access. Instead, it lets users define Storage Scopes and Contact Scopes to include specific files or contacts they want to share with an app.

These advanced permissions are paired with a complete lack of bloatware. Besides avoiding pre-installed Google services that request extensive permissions, GrapheneOS doesn’t come with a bunch of stock apps that access different parts of the system without your knowledge or drain the phone’s performance and battery.

For additional privacy, GrapheneOS lets you create user profiles. All app data is saved within a profile, so the same app doesn’t share it between profiles. This can be useful if you’re sharing a device or juggling personal tasks and work on a single phone.

4. Advanced Locking Features

GrapheneOS comes with several features that prevent theft and unauthorized access to your phone. The most notable ones include:

  • PIN scrambling: Randomizes the number layout on the lock screen to help ward off smudge attacks or shoulder-surfing
  • Two-man unlock: A form of two-factor authentication (2FA) that requires a PIN after a successful fingerprint unlock
  • Auto-reboot: Lets you specify a time of inactivity after which you want the phone to reboot to wipe the data in its memory
  • USB-C port control: Prevents unauthorized USB connections when the device is locked, both at the hardware and OS levels

For emergency situations or theft threats, you can set up a so-called “duress” PIN or password. After entering it, your device will be securely wiped so that data doesn’t fall into the wrong hands. In addition to files, media, and contacts, the wipe includes any eSIM profiles stored on the phone, which can prevent number misuse and identity theft.

How Does GrapheneOS Handle Updates and Security Patches?

Regular security patches and updates are the cornerstone of device protection, so GrapheneOS pays special attention to them. The OS automatically checks for updates every six hours or so when your phone is connected to the internet and downloads any available updates in the background.

All updates are downloaded to a secondary partition and become active when you reboot the phone. Thanks to rollback protection, failed or incomplete updates won’t brick your phone—it will simply fall back to the previous stable version.

Unlike many operating systems, GrapheneOS supports incremental patches. This means that only the changed versions of the OS are downloaded instead of full packages. The result is a more streamlined and ongoing update process that saves bandwidth.

For increased safety, GrapheneOS cryptographically signs all update packages. Your device verifies each signature to ensure the update server cannot send outdated or modified OS versions. If a tampered update is detected, it will automatically be rejected.

How To Ensure Security Beyond Device-Level Protection

GrapheneOS offers impressive security features that bring greater peace of mind than regular Android. Still, no OS can completely eliminate security risks. You must also consider an attack vector that has little to do with your phone’s OS: mobile networks.

Traditional cellular carriers like undermine secure software by leaving room for many types of serious network attacks, from SIM swaps to network interceptions and eavesdropping. That’s why they’ve fallen victim to , as well as a massive nationwide attack known as the .

Just as you might replace a traditional OS like Android with GrapheneOS, you should also consider leaving Big Telco for a . Paired with a hardened OS, it can drastically lower your exposure to network-level theft, interception, data exploitation via third parties, or surveillance.

If the peace of mind you get with such robust protection sounds appealing, switch to .

Cape: The Mobile Carrier Built for Security and Privacy

Cape is a privacy-first mobile carrier designed to keep your communications safe from surveillance and misuse. Unlike traditional cell phone plan providers, our business model centers around providing you with premium and secure call, text, and data, rather than harvesting and selling your information.

Our service is built from the ground up with privacy and security at its core, offering unique features like:

Feature

Description

Cape doesn’t ask for your name, address, or Social Security number. We collect only what’s required to provide service—and keep it for the shortest time possible.

Traditional carriers use a fixed International Mobile Subscriber ID (IMSI), making your device trackable. Cape automatically rotates your IMSI every 24 hours, which makes tracking a lot more harder.

Most U.S. carriers store your call and text metadata for years, sometimes indefinitely. Cape is built to forget, so call data records (CDRs) are deleted after just 24 hours.

Legacy protocols like SS7 enable tracking and interception. Cape verifies your device’s physical location before network attachment and automatically blocks suspicious connections.

Many services ask for your phone number, but sharing it exposes you to spam, scammers, data brokers, and a variety of other risks. VoIPs, on the other hand, don’t work with 2FA, cost extra, and aren’t encrypted. Cape gives you two free SMS/MMS lines that are end-to-end encrypted.

Cape nullifies the threat of SIM swapping by completely removing humans from the loop. During signup, you receive a 24-word phrase that generates a private key tied to your number. Only you, not even Cape, can move your number to a new device or carrier.

Traditional voicemail systems are outdated, unencrypted, and another security hole bad actors can exploit to gain access to your sensitive information. Cape encrypts all voicemails, ensuring only you can access them.

While roaming, your phone connects to local telecom providers to enable service that’s prone to interception. Cape provides you with peace of mind by routing your traffic through our U.S.-based mobile core to keep your identity and communications private.

Ditch Legacy Carriers: Get Cape Today

Cape is a “Heavy” Mobile Virtual Network Operator (MVNO), meaning we and provision our own SIMs. This gives us full control over how accounts are authenticated and what data is collected (and for how long), and is how we are able to provide privacy and security features no other carrier on the market can offer.

and enjoy the peace of mind, knowing you are fully protected against scammers, hackers, bad actors, and other mobile threats.

To help protect more than just your phone, we’ve partnered with Proton. As a new Cape subscriber, you can choose between for just $1 for six months.

1

Note: We aim to update this page regularly, but for the most up-to-date information on GrapheneOS-supported devices, please refer to the official website at .

Share it

Signup Callout

Switch to Cape,
America's privacy-first mobile carrier.

Protect yourself with premium, secure cell service.

Sign up now