How to Install GrapheneOS on Your Pixel Phone

    A complete step-by-step guide to installing GrapheneOS on your Google Pixel using the official web installer. No command line needed.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated August 2026 · 7 min read

    GrapheneOS is a privacy and security-focused mobile operating system built on Android. It runs on Google Pixel phones, with hardened privacy and security baked into the operating system itself, while maintaining everyday smartphone functionality. This guide walks the entire installation using the official web installer — no terminal, no coding, about 10 minutes.

    Good to know

    Compatible devices: GrapheneOS supports Pixel 6 and newer — including the a-series, Pro, Fold and Tablet models. Carrier-locked devices generally can't be unlocked: use an unlocked Pixel for the smoothest experience.

    Before you start: what you'll need

    • A Google Pixel (Pixel 6 or newer, unlocked)
    • A USB-C cable with data-transfer capability — ideally the one it came with (charge-only cables won’t work)
    • A computer with a supported browser: Chrome, Edge, Chromium or Brave (Shields off)
    • A stable internet connection — the OS image is around 2 GB

    Important

    This process erases the phone — completely. Unlocking the bootloader and installing GrapheneOS wipes all data on the device, and there is no undo. If this phone has anything on it you care about — photos, contacts, authenticator codes, chat history — back it all up first. A brand-new phone can skip this worry entirely.

    Tip

    Brand-new or freshly factory-reset Pixel? Race through the minimal stock setup, skipping the Google sign-in — but make sure the phone is connected to the internet (Wi-Fi or cellular) before you start the install. This lets any carrier activation finish in the background so it can't interrupt the process, and lets you grab waiting updates under Settings > System > System update — current firmware gives the installer the smoothest connection.

    Install GrapheneOS, step by step

    1

    Enable Developer Options

    The controls you need are hidden behind Android's developer menu — unlocking it is a famous little ritual. From the home screen, swipe up to open your apps and tap Settings, then scroll all the way down the list and open About phone. Head to the very bottom to find Build number and tap it seven times, quickly — after a few taps Android starts counting you down (“you are now 3 steps away from being a developer…”), asks for your PIN to confirm, and then declares it: “You are now a developer!”

    9:41

    Thu, Aug 28

    Location unavailable

    Settings
    Gemini
    Play Store
    Gmail
    Photos
    YouTube
    G

    From the Pixel home screen into Settings, down to About phone, tapping Build number through the countdown toasts and PIN to the You are now a developer message

    2

    Enable OEM unlocking

    Now Settings > System > Developer options — find OEM unlocking and switch it on. Android shows an “Allow OEM unlocking?” warning (it turns off some device-protection features by design); tap Enable and the toggle flips on.

    9:41

    About phone

    Battery information

    Device identifiers

    IP address

    fe80::a043:b7ff:fe04:9b63 · 192.168.0.168

    Wi-Fi MAC address

    To view, choose saved network

    Device Wi-Fi MAC address

    c0:1c:6a:9d:05:64

    Bluetooth address

    c0:1c:6a:9d:8f:1f

    Uptime

    4:22:28

    Send feedback about this device

    Build number

    BP41.250725.006

    You are now a developer!

    Pixel Developer options screen — turning on the OEM unlocking toggle and confirming the Allow OEM unlocking warning dialog

    Good to know

    This is the switch that permits replacing the operating system. If it's greyed out, connect to the internet and wait at least 5 minutes — it often becomes available once the phone checks in. Still greyed out? Restart the phone and try again. If it stays grey after that, the phone is likely carrier-locked and can't take GrapheneOS.
    3

    Boot into Fastboot Mode

    Time to power down and reboot into the bootloader. Hold Power + Volume Up together until the power menu appears, then tap Power off. Give it 10–15 seconds to shut down fully — wait until the screen is completely dark before continuing. Then hold Power + Volume Down together and keep holding until the Fastboot Mode screen appears — a black screen with device details and a red warning triangle. Don't press anything else; the phone just waits here for the installer.

    +-

    Developer options

    Use developer options

    Memory

    Memory profiling disabled

    Bug report

    Desktop backup password

    Desktop full backups aren't currently protected

    Stay awake

    Screen will never sleep while charging

    OEM unlocking

    Allow the bootloader to be unlocked

    Running services

    View and control currently running services

    WebView implementation

    Vanadium System WebView

    Automatic system updates

    Apply updates when device restarts

    Hold Power + Volume Up

    Pixel Fastboot Mode screen with device information — the phone paused waiting for a connection

    4

    Open the web installer on your computer

    Move over to your computer now. Open a supported web browser — Chrome, Edge, Brave or Chromium (not Firefox or Safari) — and go to grapheneos.org/install/web. Plug your phone into the computer with its USB cable while it sits on the Fastboot Mode screen.

    Scroll down the page to the Unlocking the bootloader section and click Unlock bootloader. Your browser pops up a device picker — click your Pixel to select it, then click Connect. When the page shows “Bootloader unlocking triggered successfully”, the browser and phone are talking to each other.

    Web installer | Install | GrapheneOS
    +
    grapheneos.org/install/web
    GrapheneOSFeaturesInstallBuildUsageFAQReleasesSource

    Web installer

    This is the WebUSB-based installer for GrapheneOS and is the recommended approach for most users.

    If you have trouble with the installation process, ask for help on the official GrapheneOS chat channel.

    Table of contents

    • Prerequisites
    • Enabling OEM unlocking
    • Flashing as non-root
    • Booting into the bootloader interface
    • Connecting the device
    • Unlocking the bootloader
    • Obtaining factory images
    • Flashing factory images
    • Locking the bootloader
    • Post-installation

    Unlocking the bootloader

    Press the button below to unlock the bootloader, which enables flashing the OS and firmware:

    The command needs to be confirmed on the device and will wipe all data. Use one of the volume buttons to switch the selection to accepting it and the power button to confirm.

    Obtaining factory images

    You need to obtain the GrapheneOS factory images for your device to proceed with the installation process.

    Press the button below to start the download:

    The GrapheneOS web installer at grapheneos.org/install/web — scrolling to Unlocking the bootloader, clicking Unlock bootloader, and the browser device picker to select the Pixel and Connect

    5

    Unlock the bootloader

    Now look at your phone. It's showing a confirmation with “Do not unlock the bootloader” selected and a warning that unlocking will erase the device. Press Volume Down once to change the selection to “Unlock the bootloader”, then press the Power button to confirm. The phone wipes, restarts, and returns to the Fastboot Mode screen — now reading Device state: unlocked.

    Leave the phone on this screen — don't press Start. It waits here while the next steps run from your computer.

    +-
    Do not unlock the bootloader

    Press the Volume keys to select different menu

    If you unlock the bootloader, you will be able to install custom operating system software on this phone. A custom OS is not subject to the same level of testing as the original OS, and can cause your phone and installed applications to stop working properly. Software integrity cannot be guaranteed with a custom OS, so any data stored on the phone while the bootloader is unlocked may be at risk. To prevent unauthorized access to your personal data, unlocking the bootloader will also delete all personal data on your phone.

    On the phone, the bootloader unlock confirmation — pressing Volume Down to change Do not unlock the bootloader to Unlock the bootloader, then Power to confirm, and the phone restarting to Fastboot with Device state unlocked

    6

    Download and flash GrapheneOS

    Back in the browser, scroll to Obtaining factory images and click Download release — the installer fetches the correct image for your exact Pixel (around 2 GB) and a progress bar fills to Downloaded release. Then, just below, click Flash release. The installer does the rest automatically: flashing the firmware, rebooting the phone into the bootloader, and flashing the OS, with the progress bar tracking the whole way.

    Web installer | Install | GrapheneOS
    +
    grapheneos.org/install/web
    GrapheneOSFeaturesInstallBuildUsageFAQReleasesSource

    Obtaining factory images

    You need to obtain the GrapheneOS factory images for your device. Press the button below to start the download:

    Flashing factory images

    The initial install will be performed by flashing the factory images. This will replace the existing OS installation and wipe all existing data.

    Locking the bootloader

    Locking the bootloader is important as it enables full verified boot. In the bootloader interface, set it to locked:

    The web installer — clicking Download release and its progress bar filling, then Flash release and its progress bar filling through the reboots to Flashing complete

    Important

    Do not touch the phone or the cable while it flashes. Interrupting the process — unplugging, pressing buttons, or letting the computer sleep — can leave the OS half-installed and, in the worst case, render the device unusable. Let it run to completion; it reboots itself a few times, and if the browser asks to reconnect the device, that's normal — click to reconnect and keep waiting.
    7

    Lock the bootloader

    With the OS flashed, scroll down to Locking the bootloader and click Lock bootloader. Locking is what re-arms verified boot, so that only genuine, unmodified GrapheneOS can ever run — it’s the move that completes your device’s security, so don’t skip it. A moment after you click, the page confirms with “Bootloader locking triggered successfully” and the phone shows a final confirmation for you to accept.

    Web installer | Install | GrapheneOS
    +
    grapheneos.org/install/web
    GrapheneOSFeaturesInstallBuildUsageFAQReleasesSource

    Locking the bootloader

    Locking the bootloader is important as it enables full verified boot. It also prevents using fastboot to flash, format or erase partitions. Verified boot will detect modifications to any of the OS partitions and it will prevent reading any modified / corrupted data. If changes are detected, error correction data is used to attempt to obtain the original data at which point it's verified again which makes verified boot robust to non-malicious corruption.

    In the bootloader interface, set it to locked:

    The command needs to be confirmed on the device and will wipe all data. Use one of the volume buttons to switch the selection to accepting it and the power button to confirm.

    The GrapheneOS web installer Locking the bootloader section — clicking Lock bootloader and the Bootloader locking triggered successfully confirmation

    8

    Confirm the lock on your phone

    Look at your phone one last time. It shows a confirmation with “Do not lock the bootloader” selected. Press Volume Down once to change the selection to “Lock the bootloader”, then press the Power button to confirm. The phone restarts and returns to the Fastboot Mode screen — now reading Device state: locked in green. Verified boot is armed, and the install is done.

    +-
    Do not lock the bootloader

    Press the Volume keys to select different menu

    If you lock the bootloader you will not be able to install custom operating system software on this device.

    To prevent unauthorized access to your personal data, locking the bootloader will also delete all personal data on your device.

    On the phone, the bootloader lock confirmation — pressing Volume Down to change Do not lock the bootloader to Lock the bootloader, then Power to confirm, and the phone restarting to Fastboot with Device state locked

    9

    First boot and setup

    Press the Power button to start. The phone restarts and begins the boot process, finally landing on the “Welcome to GrapheneOS” setup screen — where you can pick your language, join Wi-Fi, and set a PIN to finish setting up your device.

    +-
    Start

    Press the Volume keys to select different menu

    Fastboot Mode

    Product revision: stallion MP1.0 A1

    Bootloader version: stallion-17.0-15199480

    Baseband version: g5400i-260317-260429-B-15308590

    Serial number:

    Secure boot: PRODUCTION

    NOS production: yes

    DRAM: 8GB Hynix

    UFS: 128GB SKHynix

    Device state: locked (unlockable)

    Boot slot: b

    Enter reason: reboot bootloader

    UART: disabled

    On the phone, the Fastboot Start screen — pressing Power to boot, the screen going dark, then GrapheneOS starting with the yellow verified-boot screen: Your device is loading a different operating system, g.co/ABH, and the device verified-boot ID

    Good to know

    The yellow screen is normal — not an indication of any compromise. It’s verified boot confirming your system is genuine, unmodified GrapheneOS, and you’ll see it every time you restart this phone. Take note of the boot ID: it can be compared against your device’s model on the same web installer page — a good way to confirm the integrity of your operating system.

    You're on GrapheneOS — now the good part

    Congratulations — your Pixel is now running GrapheneOS, and you’ve joined a growing community of people who take their privacy and security into their own hands. But here’s the honest truth: the OS is only the foundation. GrapheneOS hardens the device and strips out Google’s tracking, yet its real power comes down to how you use it — the accounts you sign into, the apps you install, and the habits you build around them. A hardened phone still leaks if it’s wired straight back into the same data-hungry services it was meant to escape. So treat this as the starting line, not the finish — where you go next is what turns a clean install into a genuinely private phone:

    Cut Google out entirely

    Run with no Google at all — a private, Proton-based account stack, with apps from Aurora Store and F-Droid.
    Set up your device de-Googled

    Need your Google apps?

    Add Google Play inside GrapheneOS's sandbox for the apps that need Google services, without giving it system-level access to your phone.
    Use Google, sandboxed

    Round out your phone

    The messaging, browsing, maps, email and photo apps worth pairing with your new private phone.
    Add the best privacy apps

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security