GrapheneOS, a modified version of the Android operating system known for its enhanced security and privacy features, has introduced a new feature called "secure paste." This feature changes how Android handles clipboard content, allowing an application to read only what it has copied itself, not what other apps have copied. The code for this feature is currently in a pending pull request and is enabled by default, meaning users must actively choose to use it for added protection. Clipboard security in Android has evolved over time. Starting with Android 10, only the app currently in use and the default keyboard were allowed to access the clipboard, limiting background apps' access. Android 12 introduced notifications when an app accessed clipboard content, and Android 13 automatically cleared the clipboard after a period of inactivity. However, these changes didn't fully resolve the issue of apps reading clipboard content without user consent. In March 2023, Microsoft reported that the SHEIN app, which had been downloaded over 100 million times, periodically accessed the clipboard and sent any content containing a dollar sign and a "://” to a remote server. This behavior wasn't blocked by Android 10 because the app was in the foreground. Although the behavior stopped after a report to Google in May 2022, the underlying security flaw remained unresolved. GrapheneOS's secure paste feature tackles this issue by changing the rules of access rather than just adding warnings. An app that requests clipboard access is informed that content exists, and it can check the type, timestamp, and formatting, but the actual content is not directly accessible. The "Paste" function still works because it's initiated by the user, whether through the text selection bar, keyboard, accessibility service, or shortcut. For apps that use their own selection bar, like those built with Flutter, the "Paste" button appears in the default keyboard. The secure paste setting is available in both global and per-app configurations and is enabled by default to prevent compatibility issues with existing apps. Users must manually switch to "paste-only" mode for apps they don’t trust to gain full protection. The code for this feature has been publicly visible in a pull request since August 22 but has not yet been officially merged. GrapheneOS plans to integrate it soon, though no exact date has been given. This feature only restricts reading access and does not prevent apps from writing to the clipboard to override user content. In addition to secure paste, GrapheneOS has also redesigned its Messaging app using the Compose framework. The project aims to handle RCS (Rich Communication Services) directly within the app, including end-to-end encryption, to reduce reliance on Google Messages. While RCS works well on GrapheneOS with Google's Play layer, the goal is to eventually support RCS without requiring Google's infrastructure, depending on operator cooperation. Google has restricted RCS on rooted devices and some alternative ROMs since 2024, but GrapheneOS has found a way around this. This shows the potential for a standalone RCS client, though it remains uncertain whether operators will accept GrapheneOS's version. For now, users on GrapheneOS are advised to keep an eye on the secure clipboard feature, as it will offer even stronger protection against apps that misuse clipboard access.