Basic Security Pixel 9a with GrapheneOS

Last updated
Aug 16, 2026
Mobile brand
Google Pixel
Mobile model
Pixel 9a
Mobile operating system
Custom Android ROM
Mobile OS version
Android 17
Mobile security update support
Supported - still receiving security updates
Mobile system updates
Automatic updates
App store(s)
    • Other APT/APK sources
App updates
Auto-update on any connection
Screen lock method
PIN
Biometric security
    • None
SIM and mobile number protection
    • Not protected
Stolen Device Protection
Off
Unknown tracker alerts
    • Off
Find a lost device
    • Off
Security and privacy apps
GrapheneOS built-in security with Android security preview releases, usually a couple each month.

All GrapheneOS built-in exploit protections enabled:
  • Hardened memory allocator
  • Memory tagging
  • Secure app spawning
  • Native code debugging
  • WebView JIT
  • Dynamic code loading via memory
  • Dynamic code loading via storage
GrapheneOS features overview

App updates via GOS App Store, Accrescent and Obtainium.
Quad9 DNS
Firewall and VPN apps
None
Mobile browsers
Built-in Vanadium with ad blocking and hardened WebView
Password and passkey manager
None
Phone & Caller ID
Fossify Phone
Messaging
Fossify Messages
Music & Podcasts
Auxio
Photo & Video
Fossify Gallery
Entertainment
Via Vanadium
Note-taking
Fossify Notes
Cloud storage
None
Games
None
Android launcher
GrapheneOS Launcher with Android themed icons.
Two-factor authentication
None
File and photo backups
Automatic built-in Seedvault system backup
Manual file backup
Subscriptions
    • None
Notable changes
GrapheneOS with lean and mean configuration. All GOS-specific security features enabled. Almost all Fossify apps. App updates via GOS App Store, Accrescent and Obtainium. No bloat. No Google. No AI. No BS.

Moving to GOS was hands-down the best move I've made in tech. (y)(y):cool:
Feedback preference

Only essential issues, please

oldschool

Level 89
Verified
Top Poster
Well-known
High Reputation
Forum Veteran
I figured I'd post my Pixel 9a setup for curious minds.

App updates via GOS App Store, Accrescent and directly from source via Obtainium.

PIN scrambling enabled.

NB Moderators: Graphene has no Stolen Device Protection, no Tracker Protection but does have hardened USB protection above and beyond stock OEM Android and Apple.
 
Last edited:
I figured I'd post my Pixel 9a setup for curious minds.

App updates via GOS App Store, Accrescent and directly from source via Obtainium.

PIN scrambling enabled.

NB Moderators: Graphene has no Stolen Device Protection, no Tracker Protection but does have hardened USB protection above and beyond stock OEM Android and Apple.
Congrats on running Graphene. I used to do that but then I got old and wise. I realized that no OS level protection will protect me from folks who truly want what's on my phone. So why the heck make life more inconvenient for myself?
 
Nice i also use it for years, now on pixel 10a, without any external store just the built'in one, IVPN and just replace the native keyboard with Heliboard and quik for sms, and Comaps when am lost;), and disable sensors autorisation for few apps like clock, calc.......and for my blue eyes i set simulate color space to monochromacy.
PS : imho, using grapheneos with common sense automatically level up your unverified status to advanced plus security.
PS 2 : Duress password is also a cool feature.
 
Last edited:
In that case I apologize; it appears that GOS has gone leaps and bounds from it's mid 2010's times where only specific apps were able to run on it.
No problem. AFAIK, certain banking apps are the biggest issue for users. Oh, and Google Pay won't run.

GOS is about ready to go mainstream.
 
I figured I'd post my Pixel 9a setup for curious minds.

App updates via GOS App Store, Accrescent and directly from source via Obtainium.

PIN scrambling enabled.

NB Moderators: Graphene has no Stolen Device Protection, no Tracker Protection but does have hardened USB protection above and beyond stock OEM Android and Apple.
for USB protection as an extra level of security that does not depend on software as a control is to employ a USB charger condom when utilizing any USB device as just a charging system rather than data transfer system. The "condom" "removes" the data pins and employs only the charge pins making data exfiltration via USB extremelly difficult to impossible. I have mine on a keychain so it's always with me.
 
Wow you're tagged as Basic Security, imho this is not the right sentence, GOS give you privacy and security out of the box, so in that case alls android, apple based smartphone should get unsecure sentence, but the judge may think GOS in mostly for criminals, BUT NO, i use it because am fed up being spying all the time, just like using Linux over windows or use self hosted SearXNG + Nginx meta engine over alls folks like google search, startpage, duckduck, brave...........
read read read please: GrapheneOS features overview
Just my two cents.
 
Last edited:
It is tagged as Basic Security according with forum rules for this section, since not all "security aspects" are covered in this configuration, in fact, I was "benevolent" hehe because being strict with the rules, probably should be tagged as At Risk.
 
Nice i also use it for years, now on pixel 10a, without any external store just the built'in one
Same, plus using Obtainium.
replace the native keyboard with Heliboard and quik for sms
Nice. I use FUTO keyboard and Fossify Messages.
Comaps when am lost
I use it too.
and disable sensors autorisation for few apps like clock, calc.
Same again. I love the extensive separate permissions toggles. No OEM Android has anything like it.
 
One other BIG advantage of using grapheneOS is that you can opt-in for security preview release, grapheneos team can access oem CVE's patchs before all others including google itself, for example last preview security release from yesterday covered CVE's til' january 2027, really MAJOR SECURITY breach improvements :
All of the Android 17 security patches from the current September 2026, October 2026, November 2026, December 2026 and January 2027 Android Security Bulletins are included in the 2026081301 security preview release. List of additional fixed CVEs:

  • Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28653, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884, CVE-2026-49918, CVE-2026-49921, CVE-2026-49926, CVE-2026-49927, CVE-2026-49932, CVE-2026-49933, CVE-2026-55256, CVE-2026-55265, CVE-2026-55268, CVE-2026-55269, CVE-2026-55273, CVE-2026-55277, CVE-2026-55280, CVE-2026-58814, CVE-2026-58820, CVE-2026-58823, CVE-2026-58835, CVE-2026-58865, CVE-2026-58868, CVE-2026-58876, CVE-2026-58880, CVE-2026-58882, CVE-2026-58984
  • High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-0053, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49878, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885, CVE-2026-49887, CVE-2026-49895, CVE-2026-49896, CVE-2026-49912, CVE-2026-49913, CVE-2026-49914, CVE-2026-49923, CVE-2026-49924, CVE-2026-49925, CVE-2026-49931, CVE-2026-49934, CVE-2026-49935, CVE-2026-49937, CVE-2026-55257, CVE-2026-55261, CVE-2026-55262, CVE-2026-55263, CVE-2026-55264, CVE-2026-55266, CVE-2026-55270, CVE-2026-55271, CVE-2026-55272, CVE-2026-55278, CVE-2026-55279, CVE-2026-55282, CVE-2026-55284, CVE-2026-55286, CVE-2026-55287, CVE-2026-55288, CVE-2026-55289, CVE-2026-55290, CVE-2026-55292, CVE-2026-55294, CVE-2026-58815, CVE-2026-58817, CVE-2026-58821, CVE-2026-58822, CVE-2026-58834, CVE-2026-58836, CVE-2026-58837, CVE-2026-58838, CVE-2026-58841, CVE-2026-58853, CVE-2026-58854, CVE-2026-58856, CVE-2026-58857, CVE-2026-58859, CVE-2026-58860, CVE-2026-58866, CVE-2026-58867, CVE-2026-58868, CVE-2026-58869, CVE-2026-58870, CVE-2026-58871, CVE-2026-58872, CVE-2026-58875, CVE-2026-58877, CVE-2026-58879, CVE-2026-58884, CVE-2026-58885, CVE-2026-58886, CVE-2026-58933, CVE-2026-58934, CVE-2026-58935, CVE-2026-58937, CVE-2026-58938, CVE-2026-58943, CVE-2026-58944, CVE-2026-58945, CVE-2026-58946, CVE-2026-58949, CVE-2026-58951, CVE-2026-58953, CVE-2026-58954, CVE-2026-58955, CVE-2026-58956, CVE-2026-58958, CVE-2026-58960, CVE-2026-58961, CVE-2026-58962, CVE-2026-58963, CVE-2026-58964, CVE-2026-58965, CVE-2026-58966, CVE-2026-58968, CVE-2026-58969, CVE-2026-58970, CVE-2026-58971, CVE-2026-58972, CVE-2026-58973, CVE-2026-58974, CVE-2026-58975, CVE-2026-58976, CVE-2026-58978, CVE-2026-58979
  • Unclassified: CVE-2026-55260, CVE-2026-58883
 
How does battery life with Graphene OS compare to battery life when you used original ROM?
From personal experience, battery duration is improved when using GOS over Stock Android, actually my pixel 10a with stock rom give me about 2 days with normal usage, when GOS on board and my settings, i've easily four full days of use, i think is mainly because less things running in background (AI, playstore, all crap's bundled with android, the google pixel are less bloated than other brand).
 
On my Nothing Phone 2 I tried Lineage OS as it was officially released for my device model. Battery life was notably better.

Edit:

I apologise I thought you were talking about LineageOS.
Yeah, I'm asking because I also noticed significant battery increase on my Poco X5 Pro after uninstalling all HyperOS garbage and using Control D system-wide.
 
Community
Security tip
Use FileVault thoughtfully. Enable FileVault where appropriate and keep its recovery method accessible. Encryption protects stored data, while backups protect your ability to recover it.
Back
Top