android A field note by Vikrant Sharma
Google shipped the Pixel 11 with weaker memory protection
The Pixel 11 drops hardware memory tagging that was standard on the Pixel 8 and 9. GrapheneOS called it out on Twitter.
The GrapheneOS team noticed that Google’s Pixel 11 shipped without Memory Tagging Extension support, a hardware security feature that was present in the Pixel 8 and 9. MTE catches a class of memory corruption bugs by tagging pointers and checking them at runtime. It is not theoretical protection. It stops use-after-free and buffer overflow exploits that attackers use in the wild. The Pixel 11 uses the Tensor G6 chip. Google could have included MTE support in the silicon, but did not. The Pixel 8 and 9 both had it. This is a step backwards in a product line that markets itself on security. GrapheneOS ships MTE enabled by default on devices that support it. They have measured the performance overhead at around 10 to 15 percent depending on workload. That overhead exists because every memory access gets checked. The tradeoff is worth it if you care about exploit resistance. Apparently Google decided it was not worth it for the Pixel 11. The frustrating part is that this was a solved problem. The Pixel 8 shipped with MTE in 2023. Dropping it two generations later signals that hardware security features are negotiable, not baseline. If you are buying a phone specifically for security, you now have to check the spec sheet for something that should have been standard.