Open-source project
BareBrowser/bare-browser avatar
BareBrowser/bare-browser

Bare Browser: a de-Googled Chromium patch series for Android

Bare is a de-Googled Chromium build for Android, built for privacy, control, and freedom on the web. It strips Google tracking, telemetry, and AI integration while keeping browser extensions and uBlock Origin. It adds background video playback, saving media from sites that normally block it, your choice of download manager, and more.

427 stars5 forksPythonBSD-3-Clause

At a glance

What is it?
Bare is 128 patches against one pinned Chromium Desktop Android revision, not a fork. It keeps Manifest V2 and uBlock Origin, removes Google's AI and telemetry surfaces, and is built by one person on a Pixel 10 Pro XL.
Who is it for?
Bare suits Android users who want desktop extensions, uBlock Origin and no AI surfaces, and who accept an alpha build from a single maintainer. It is not for anyone who needs a stable daily browser on a non-arm device or who wants a signed APK from a vendor: the repository ships a builder, not a download.
Can I use it commercially?
Yes. BSD-3-Clause is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 19 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Bare changes, and who it is aimed at

Chromium's Desktop Android build supports real browser extensions, which mobile Chrome does not. That is the opening Bare exploits. The README frames the project as a response to that build still shipping Google's AI stack, phoning home on a schedule, and handing links to other apps. Bare is the subtraction plus a set of additions: background video playback, saving media from sites that stream in pieces, a choice of download manager, and links that stay in the browser.

The intended user is specific. Someone on Android who wants uBlock Origin rather than a Lite substitute, who wants Bitwarden and Dark Reader as the desktop versions, and who is willing to build or trust a build made by one person. The README says it is built and used on a Pixel 10 Pro XL and that there is no company behind it. That is a fair statement of scope: this is not an enterprise browser with an MDM story.

A patch series, not a fork: how the 128 patches sit on Chromium

The architecture is the most interesting decision here. Bare is not a fork with a diverged tree. It is 128 patches against one pinned revision of Chromium Desktop Android, base 153.0.8010.27 at commit ac9b84a0. The repository holds exactly the difference between stock Chromium and Bare, and nothing else. The README states the size as 14,605 insertions across 341 files.

That shape has consequences. Every change stays readable and reviewable, because a reviewer reads a patch rather than diffing two large trees. It also means upgrades are rebases: when Chromium moves, the patch set has to be reapplied and whatever conflicts repaired by hand. The README points to docs/patches.md for the full list, including what is removed by build flag instead of by patch, and what is deliberately kept. That last category matters more than the first, and the project treats it that way.

Building Bare in Docker on arm64 and arm

The repository ships a builder rather than a downloadable APK. The top level contains builder.sh, docker/, docker-compose.yml and an exchange/ directory. The compose file defines a single service, chromium-builder, pinned to platform linux/amd64, built from the ./docker context and tagged chromium-android-builder:local. It asks for 2gb of shared memory and mounts a named volume called chromium-android-source at /work, plus the local ./exchange directory at /exchange.

yaml
services:
  chromium-builder:
    platform: linux/amd64
    build:
      context: ./docker
    image: chromium-android-builder:local
    container_name: chromium-android-builder
    stdin_open: true
    tty: true
    shm_size: 2gb
    volumes:
      - chromium-source:/work
      - ./exchange:/exchange

The target is set for mobile: is_desktop_android = true, with target_cpu = "arm64" and "arm". The README gives version 1.0.0-alpha.3, versionCode 801000065 for arm64 and 801000060 for 32-bit arm. BUILDING.md is the file to read before running anything, since the README does not spell out the build invocation itself. Expect a Chromium build to be long and to want disk; the compose file's shm_size of 2gb is the only resource hint the repository gives.

uBlock Origin, Manifest V2 and the extensions toolbar

The feature that separates Bare from most mobile Chromium derivatives is that it keeps Manifest V2 working. That is why the bundled content blocker is the full uBlock Origin rather than uBlock Origin Lite, and the README notes it is shipped exactly as its author publishes it and can be removed like anything else. Extensions appear in a toolbar on phone layouts, pin-able, which the README lists among the patches.

There is a real trade-off in keeping MV2 alive. Google's removal of MV2 is a moving target, so this is a patch that will need maintenance as the upstream tree changes, not a one-time deletion. The same applies to the Google callback removals: patch 0085 dropped twelve components, among them the Privacy Sandbox set, on the grounds that they buy nothing here.

What still talks to Google, and why

The Network behaviour section is unusually honest and is the part to read before trusting any privacy claim. The README says it was measured on a Pixel 3 running Android 12 and an Android 17 emulator by watching sockets opened under Bare's own uid on a wiped profile. On a second and later start with an established profile, one host is contacted without being asked: update.googleapis.com, Chromium's component updater.

It is kept deliberately. The components left registered are ones the project classifies as security or web compatibility: CRLSet for certificate revocation, PKIMetadata for Certificate Transparency, SSLErrorAssistant, FileTypePolicies, OriginTrials, Widevine, and SafetyTips with CrowdDeny applied locally. The README acknowledges the cost plainly: registration tells Google an install exists, with a component id, a version, an install date and a cohort. Anyone who requires zero contact with Google infrastructure should treat that sentence as disqualifying. Everyone else should read it as a documented boundary rather than a hidden one.

Alpha status, one maintainer, and the upgrade bill

Three releases exist: v1.0.0-alpha.1-rc2 on 2026-08-26, v1.0.0-alpha.2-rc3 on 2026-08-28, and v1.0.0-alpha.3 on 2026-09-11. The last push to the repository was on 2026-09-11. The version string itself says alpha, and the release cadence over that fortnight shows active work rather than a finished product.

The realistic cost is the rebase. Chromium's Desktop Android target is not a frozen base, so each upstream milestone means reapplying 128 patches and resolving conflicts. The README's own framing, that every change stays readable and reviewable, is the mitigation for that cost, not an elimination of it. A user who cannot build from source depends entirely on the maintainer publishing a build, and the repository does not present itself as a distribution channel.

The licence is BSD-3-Clause, with a LICENSE and NOTICE file at the top level. Chromium itself carries its own licensing and third-party notices, and the repository keeps a third_party/ directory alongside them. Redistributing a build means carrying those notices through; this is a packaging question to settle with whoever handles compliance, not a legal opinion.

How Bare differs from Brave on Android

The obvious comparison for an Android user weighing privacy browsers is Brave. The approaches diverge at the base. Brave is a product with a company behind it, distributed as a signed APK through app stores, and its blocking is built into the browser engine rather than exposed as the full uBlock Origin extension. Bare is a patch set against Chromium Desktop Android, built locally through Docker, and its blocking comes from an extension the user can inspect, pin, or remove.

That means Brave wins on installation and support, and Bare wins on what you can verify. With Bare you can read every patch, see exactly which Google components were dropped and which were kept, and read a socket-level account of what leaves the device. With Brave you get a maintained binary and a privacy policy. Neither is strictly better; they answer different questions. Someone who wants a browser today should take the binary. Someone who wants to know what the binary does should read the patches.

Editorial conclusion

Bare suits Android users who want desktop extensions, uBlock Origin and no AI surfaces, and who accept an alpha build from a single maintainer. It is not for anyone who needs a stable daily browser on a non-arm device or who wants a signed APK from a vendor: the repository ships a builder, not a download. Before adopting it, read docs/patches.md to confirm the removals match what you want, and check Network behaviour for the update.googleapis.com contact that is kept on purpose.

Frequently asked questions

Is using Brave browser illegal?

This concerns Brave, not Bare Browser, and the Bare repository says nothing about it. What can be stated from the repository is that Bare is licensed BSD-3-Clause and that the README says it is not affiliated with Google or the Chromium project.

Why is Brave closing?

The Bare repository does not discuss Brave's status, so there is nothing to answer here about Brave. Bare itself is not archived: the last push was on 2026-09-11, and the newest release is v1.0.0-alpha.3.

What is the Brave controversy?

Nothing in the Bare repository covers Brave or any controversy around it. What Bare documents about itself instead is its network behaviour: on a second and later start it contacts update.googleapis.com for Chromium's component updater, and the README names the components kept and the reason for each.

Which browser is not safe?

The Bare repository does not rank browsers by safety, so it cannot answer this generally. It does state one specific case for itself: with an established profile, update.googleapis.com is contacted without being asked, and that registration tells Google an install exists along with a component id, a version, an install date and a cohort.

Official sources

  1. BareBrowser/bare-browser on GitHub
  2. Issues
  3. License: BSD-3-Clause
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/barebrowser-bare-browser.svg)](https://hysenlabs.com/projects/barebrowser-bare-browser)