GrapheneOS is an
open-source
Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use and view the source code, design documents, or content of the product. The open source model is a decentrali ...
, privacy- and security-focused
Android operating system
An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs.
Time-sharing operating systems scheduler (computing), schedule tasks for ...
that runs on selected
Google Pixel
Google Pixel is a brand of portable Consumer electronics, consumer electronic devices developed by Google that run either ChromeOS or the Pixel version of the Android (operating system), Android operating system. The main line of Pixel products ...
devices, including
smartphone
A smartphone is a mobile phone with advanced computing capabilities. It typically has a touchscreen interface, allowing users to access a wide range of applications and services, such as web browsing, email, and social media, as well as multi ...
s,
tablets and
foldables.
History
The main
developer, Daniel Micay, originally worked on
CopperheadOS, until a schism over software licensing between the co-founders of Copperhead Limited led to Micay's dismissal from the company in 2018.
After the incident, Micay continued working on the Android Hardening project,
which was renamed as GrapheneOS
and announced in April 2019.
In March 2022, two GrapheneOS apps, "Secure Camera" and "Secure PDF Viewer", were released on the
Google Play Store
Google Play, also known as the Google Play Store, Play Store, or sometimes the Android Store (and was formerly Android Market), is a digital distribution service operated and developed by Google. It serves as the official app store for certifie ...
.
Also in March 2022, GrapheneOS reportedly released
Android 12L for
Google Pixel
Google Pixel is a brand of portable Consumer electronics, consumer electronic devices developed by Google that run either ChromeOS or the Pixel version of the Android (operating system), Android operating system. The main line of Pixel products ...
devices before
Google
Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
did, second to ProtonAOSP.
In May 2023, Micay announced he would step down as
lead developer of GrapheneOS and as a GrapheneOS Foundation director. As of September 2024, the GrapheneOS Foundation's Federal Corporation Information lists Micay as one of its directors.
Features
Sandboxed Google Play
By default
Google apps
Google Workspace (formerly G Suite, formerly Google Apps) is a collection of cloud computing, Productivity software, productivity and Collaborative software, collaboration tools, software and products developed and marketed by Google. It con ...
are not installed with GrapheneOS,
but users can install a
sandboxed version of
Google Play Services from the pre-installed "App Store".
The sandboxed Google Play Services allows access to the Google Play Store and apps dependent on it, along with features including
push notifications
Push technology, also known as server Push, refers to a communication method, where the communication is initiated by a server rather than a client. This approach is different from the "pull" method where the communication is initiated by a client ...
and in-app payments.
Around January 2024,
Android Auto
Android Auto is a mobile app developed by Google to mirror features of a smartphone (or other Android device) on a car's dashboard information and entertainment head unit.
Once an Android device is paired with the car's head unit, the system ...
support was added to GrapheneOS, allowing users to install it via the App Store. The Sandboxed Google Play compatibility layer settings adds a new permission menu with 4 toggles for granting the minimal access required for wired Android Auto, wireless Android Auto, audio routing and phone calls.
Security and privacy features
GrapheneOS introduces revocable network access and sensors permission toggles for each installed app.
GrapheneOS also introduces a PIN scrambling option for the
lock screen.
GrapheneOS randomizes
Wi-Fi
Wi-Fi () is a family of wireless network protocols based on the IEEE 802.11 family of standards, which are commonly used for Wireless LAN, local area networking of devices and Internet access, allowing nearby digital devices to exchange data by ...
MAC addresses per connection (to a Wi-Fi network) by default, instead of the Android per-network default.
GrapheneOS includes automatic phone reboot when not in use, automatic WiFi and Bluetooth disabling, and system-level disabling of USB-C port, microphone, camera, and sensors for apps. Additionally, it offers the "Contact Scopes" feature, which allows users to select which contacts an app can access.
A hardened
Chromium
Chromium is a chemical element; it has Symbol (chemistry), symbol Cr and atomic number 24. It is the first element in Group 6 element, group 6. It is a steely-grey, Luster (mineralogy), lustrous, hard, and brittle transition metal.
Chromium ...
-based web browser and
WebView implementation known as Vanadium, is developed by GrapheneOS and included as the default web browser/WebView.
It includes automatic updates, process and site-level sandboxing, and built-in ad and tracker blocking.
Auditor, a hardware-based attestation app, developed by GrapheneOS, which ''"provide strong hardware-based verification of the authenticity and integrity of the
firmware
In computing
Computing is any goal-oriented activity requiring, benefiting from, or creating computer, computing machinery. It includes the study and experimentation of algorithmic processes, and the development of both computer hardware, h ...
/
software
Software consists of computer programs that instruct the Execution (computing), execution of a computer. Software also includes design documents and specifications.
The history of software is closely tied to the development of digital comput ...
on the device"'' is also included.
Apps like Secure Camera and Secure PDF Viewer offer features such as automatic removal of
Exif
Exchangeable image file format (officially Exif, according to JEIDA/JEITA/CIPA specifications) is a standard that specifies formats for images, sound, and ancillary tags used by digital cameras (including smartphones), scanners and other system ...
metadata and protection against malicious code in PDF files.
Installation
GrapheneOS currently is only compatible with
Google Pixel
Google Pixel is a brand of portable Consumer electronics, consumer electronic devices developed by Google that run either ChromeOS or the Pixel version of the Android (operating system), Android operating system. The main line of Pixel products ...
devices, due to specific requirements that GrapheneOS has for adding support for a new device, including an unlockable bootloader and proper implementation of verified boot.
The operating system can be installed from various platforms, including Windows, macOS, Linux, and Android devices. Two installation methods are available: a
WebUSB-based installer, recommended for most users, and a
command-line
A command-line interface (CLI) is a means of interacting with software via commands each formatted as a line of text. Command-line interfaces emerged in the mid-1960s, on computer terminals, as an interactive and more user-friendly alternativ ...
based installer, intended for more experienced users.
Reception
In 2019, Georg Pichler of ''
Der Standard
''Der Standard'' () is an Austrian daily newspaper published in Vienna. It is considered a newspaper of record for Austria.
History and profile
''Der Standard'' was founded by Oscar Bronner as a financial newspaper and published its first editio ...
'', and other news sources, quoted
Edward Snowden
Edward Joseph Snowden (born June 21, 1983) is a former National Security Agency (NSA) intelligence contractor and whistleblower who leaked classified documents revealing the existence of global surveillance programs.
Born in 1983 in Elizabeth ...
saying on
Twitter
Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
, "If I were configuring a smartphone today, I'd use Daniel Micay's GrapheneOS as the base operating system."
In discussing why services should not force users to install
proprietary apps, Lennart Mühlenmeier of
netzpolitik.org
netzpolitik.org is a German language news website on digital rights and digital culture. Among other topics, it covers mass surveillance, Open-source software, open source software, Information privacy, data protection and privacy and net neutra ...
suggested GrapheneOS as an alternative to Apple or Google.
''Svět Mobilně'' and ''Webtekno'' repeated the suggestions that GrapheneOS is a good security- and privacy-oriented replacement for standard Android.
In a detailed review of GrapheneOS for
Golem.de, Moritz Tremmel and Sebastian Grüner said they were able to use GrapheneOS similarly to other Android systems, while enjoying more freedom from Google, without noticing differences from "additional memory protection, but that's the way it should be." They concluded GrapheneOS cannot change how "Android devices become garbage after three years at the latest", but "it can better secure the devices during their remaining life while protecting privacy."
In June 2021, reviews of GrapheneOS,
KaiOS
KaiOS is a mobile Linux distribution for keypad-based mobile phones. It is designed and optimised for affordable and low-power feature phones, while retaining access to Internet services through web apps, based on the Gecko engine. KaiOS was ...
,
AliOS, and
Tizen OS, were published in Cellular News. The review of GrapheneOS called it "arguably the best mobile operating system in terms of privacy and security." However, they criticized GrapheneOS for its inconvenience to users, saying "GrapheneOS is completely de-Googled and will stay that way forever—at least according to the developers." They also noticed a "slight performance decrease" and said "it might take two full seconds for an app—even if it’s just the Settings app—to fully load."
In March 2022, writing for ''How-To Geek'' Joe Fedewa said that Google apps were not included due to concerns over privacy, and GrapheneOS also did not include a default
app store
An app store, also called an app marketplace or app catalog, is a type of digital distribution platform for computer software called applications, often in a mobile context. Apps provide a specific set of functions which, by definition, do not i ...
. Instead, Fedewa suggested,
F-Droid
F-Droid is a free and open source app store and software repository for Android (operating system), Android, serving a similar function to the Google Play store. The main repository, hosted by the project, contains only free software, free and o ...
could be used.
In 2022, Jonathan Lamont of ''MobileSyrup'' reviewed GrapheneOS installed on a
Pixel 3, after one week of use. He called GrapheneOS install process "straightforward" and concluded that he liked GrapheneOS overall, but criticized the post-install as "often not a seamless experience like using an unmodified Pixel or an
iPhone
The iPhone is a line of smartphones developed and marketed by Apple that run iOS, the company's own mobile operating system. The first-generation iPhone was announced by then–Apple CEO and co-founder Steve Jobs on January 9, 2007, at ...
", attributing his experience to his "over-reliance on Google apps" and the absence of some "smart" features in GrapheneOS default keyboard and camera apps, in comparison to software from Google.
In his initial impressions post a week prior, Lamont said that after an easy install there were issues with permissions for Google's
Messages app, and difficulty importing contacts; Lamont then concluded, "Anyone looking for a straightforward experience may want to avoid GrapheneOS or other privacy-oriented Android experiences since the privacy gains often come at the expense of convenience and ease of use."
In July 2022, Charlie Osborne of
ZDNET suggested that individuals who suspect a
Pegasus
Pegasus (; ) is a winged horse in Greek mythology, usually depicted as a white stallion. He was sired by Poseidon, in his role as horse-god, and foaled by the Gorgon Medusa. Pegasus was the brother of Chrysaor, both born from Medusa's blood w ...
infection use a secondary device with GrapheneOS for secure communication.
In January 2023, a Swiss startup company, Apostrophy AG, announced AphyOS, which is a subscription fee-based Android operating system and services "built atop" GrapheneOS.
See also
*
Comparison of mobile operating systems
This is a comparison of mobile operating systems. Only the latest versions are shown in the table below, even though older versions may still be marketed.
About OS
Advanced controls
Accessibility features
App ecosystem
Browser ...
*
List of custom Android distributions
*
Security-focused operating system
This is a list of operating systems specifically focused on computer security, security. Similar concepts include security-evaluated operating systems that have achieved certification from an code audit, auditing organization, and trusted operati ...
References and notes
External links
*
{{Mobile operating systems
Android (operating system) software
ARM operating systems
Computing platforms
Custom Android firmware
Embedded Linux distributions
Linux distributions
Linux distributions without systemd
Mobile Linux
Operating system families
Mobile operating systems
Software using the Apache license