Titanium Browser for Android: a Vanadium-based Chromium build with extension support
Secure open-source Android browser with support for extensions
At a glance
- What is it?
- Titanium Browser for Android is a GPL-2.0 Chromium fork built on GrapheneOS's Vanadium patches, adding extension support and Manifest V2. It is for Android users who want a signed, open-source browser but cannot run GrapheneOS.
- Who is it for?
- Adopt Titanium Browser if you want a signed, open-source Chromium build on stock Android with real extension support, and you accept that the OS itself is not hardened. Do not adopt it if you can run GrapheneOS, because the README itself points to Vanadium there as the stronger option.
- Can I use it commercially?
- Yes, with conditions. GPL-2.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 8 days ago.
- What is it written in?
- Mainly Shell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Titanium Browser for Android solves, and who it is for
Stock Android ships Chrome, and Chrome does not load extensions. That is the gap this project targets. Titanium Browser for Android is a Chromium-based browser that supports extensions, distributed as a signed APK on GitHub Releases and on Google Play under the package id io.github.jqssun.helium. The Play listing still uses the old Helium name; the repository was renamed to avoid branding confusion, and the project was formerly known as Helium Browser for Android.
The audience is narrow and specific. It is for Android users who want a browser whose source they can read, whose releases they can verify, and which can run Chrome Web Store extensions. It is not aimed at people who want a hardened operating system, because the README says so directly: the warning block states that for better protection on Android you should instead use GrapheneOS with Vanadium, which additionally patches Android System WebView and hardens the kernel and memory management at the OS level. Titanium improves the browser; it cannot improve the platform underneath it.
The licence is GPL-2.0, which matters for anyone who wants to redistribute a modified build. The primary language listed for the repository is Shell, which is consistent with what the repository actually contains: build scripts and patch files rather than application source.
How the Vanadium patch stack and args.gn fit together
Titanium Browser for Android is not a fork of Chromium in the sense of maintaining a separate codebase. The repository layout makes the layering explicit. A vanadium directory and a .gitmodules file pull in the upstream project, and the README's own diagram shows two patch sets feeding into the build: generic patches under patches/*.patch and subproject patches under subprojects_patches/**/*.patch, both inherited from Vanadium. On top of that sit the project's own additional patches, grouped in the diagram as Feature Overrides, UI Overrides, Manifest V2 plus Secure Off Store Install Support, and Miscellaneous Fixes and Improvements.
The build itself is driven by args.gn, a GN build configuration file that sits at the top level of the repository. That file is where the Chromium build flags live. The diagram routes args.gn into a signed release, which tells you the practical shape of the project: patches plus build arguments plus a signing key produce the APK. The scripts build.sh, patch.sh and common.sh are the entry points that apply the patches and invoke the build.
One consequence of this design is that the interesting decisions are spread across patch files rather than concentrated in readable application code. If you want to know what a Titanium release changes relative to Vanadium, you read patches, not a changelog. The README does not document a per-release diff.
Installing the Titanium Browser APK and loading a first extension
The README points to GitHub Releases for the latest builds and notes that you can update between GitHub and Google Play releases seamlessly, so mixing the two sources does not lock you in. Download the APK from the releases page and install it as you would any sideloaded Android package.
Once installed, extension installation is the part worth learning first. For Chrome Web Store extensions, the README gives a specific procedure: open the Chrome Web Store, then enable Desktop site from the menu button in the top right corner, and proceed as normal. The desktop site toggle is what makes the store usable on a phone.
If you have an extension folder locally rather than a store listing, the manual path is Load unpacked. The README describes navigating to the Manage extensions page or chrome://extensions, enabling Developer mode, selecting Load unpacked, and choosing the folder through the Storage Access Framework picker. It notes that Manifest V2 extensions are supported and that loading may take a moment.
# Verify a downloaded release APK against the GitHub attestation
gh attestation verify *.apk -R jqssun/android-titanium-browserThat command uses the GitHub CLI to check the attestation for the APK you downloaded against this repository. It is the one verification step the README documents, and it is worth running before you install.
For Opera Add-ons, Microsoft Edge Add-ons, or other marketplaces, the README says targeted User Agent modifications may be required and directs you to the separate Titanium Extension for Android project for instructions. That is a real friction point: non-Chrome stores are not a first-class path.
Incognito extensions and the WebRTC IP policy trade-off
Two default behaviours are likely to surprise a new user. The first is that extensions do not run in Incognito, which the README calls OTR mode, unless you opt in per extension. The procedure is to open Manage extensions, find the extension, select Details, and turn on Allow in Incognito. There is no global switch described.
The second is WebRTC. The README states that IPs are shielded by default, and that this can break WebRTC-dependent features; it names Discord Voice as the example. The fix is a setting under the menu button, then Settings, Privacy and security, where you can change the policy to Default public interface only or Default. That is a genuine trade-off rather than a bug: the privacy-preserving default is the one that breaks voice chat, and relaxing it is a manual step the user has to take knowingly. If you spend your day in browser-based calls, you will hit this on day one.
The README also points to chrome://chrome-urls for the full list of debug URLs and chrome://flags for Experiments. These are standard Chromium surfaces, which is the point: the project keeps the familiar internals rather than replacing them.
Where Titanium Browser is the wrong choice
The clearest limitation is stated by the project itself. The warning in the README says Titanium Browser only attempts to improve security and privacy where possible, and that GrapheneOS with Vanadium provides better protection because it also patches Android System WebView and hardens the kernel and memory management at the OS level. If your threat model includes the operating system, a browser APK cannot address it, and the maintainer says as much.
A second limitation is the modular design. Advanced features including external download manager support, enhanced dark mode, and additional privacy options live in a separate project, Titanium Extension for Android. If you install only the browser, you do not get those. The README describes them as modularised to maintain a fast and native experience, which is a defensible choice, but it means the browser alone is not the whole product.
A third is the documentation surface. The README covers usage and building. It does not document rollback, does not provide a per-release changelog, and does not explain how the additional patches interact with the Vanadium patch sets. Anyone who needs to audit exactly what a given release changes will have to read the patch files themselves.
Finally, the Play listing id is io.github.jqssun.helium while the project is now called Titanium. If you are searching the store for the current name, that mismatch is a real source of confusion.
Vanadium on GrapheneOS as the alternative, and the actual difference
The alternative the README names is Vanadium on GrapheneOS. The difference is not which Chromium patches are applied; Titanium inherits Vanadium's generic and subproject patches, so the browser-level hardening overlaps. The difference is scope. Vanadium on GrapheneOS also integrates patches into Android System WebView, the component that renders web content inside other apps, and provides kernel and memory management hardening on the OS level. Titanium runs on whatever Android you already have, so WebView and the kernel are untouched.
That gives a clean decision rule. If you can install GrapheneOS on your device, the README's own recommendation is to use Vanadium there and skip Titanium. If your device is not supported by GrapheneOS, or you need a browser you can install on a normal Android phone, Titanium is the option that keeps the Vanadium patch lineage while adding extension support. The extension support is what Vanadium does not offer, and it is the reason this project exists as a separate thing.
Building your own release, signing keys and GPL-2.0
The README states that all releases are built using GitHub Actions, and that the repository provides a build script intended for the latest Ubuntu, which may also work on other Linux distributions. To build via CI, you fork the repository and supply two secrets under Settings, Secrets and variables, Actions: a base64 encoded keystore.jks, and a local.properties file containing keyAlias, keyPassword and storePassword. The workflow file references these at .github/workflows/build.yml. Then you go to Actions, select Build, and select Run workflow, entering either ubuntu-latest for a GitHub-hosted runner or self-hosted for your own hardware.
# Build script entry points in the repository root
./build.sh
./patch.sh
./common.shThose three scripts are the top-level shell entry points listed in the repository. The README does not document their individual flags, so treat the CI workflow as the supported path.
The signing setup has a practical consequence worth naming: your fork produces builds signed with your key, not the maintainer's, so they will not update over an installed official release. The README's note about seamless updates applies to moving between the official GitHub and Google Play releases, not to a self-built APK.
On licence, the project is GPL-2.0. If you redistribute a modified build, the GPL's source-availability terms apply to what you distribute. That is a description of the licence text, not legal advice; check the LICENSE file and your own obligations.
Editorial conclusion
Adopt Titanium Browser if you want a signed, open-source Chromium build on stock Android with real extension support, and you accept that the OS itself is not hardened. Do not adopt it if you can run GrapheneOS, because the README itself points to Vanadium there as the stronger option. Before installing, verify the APK with gh attestation verify *.apk -R jqssun/android-titanium-browser and read the args.gn file to see which build flags the release actually uses.
Frequently asked questions
Is Titanium Browser for Android safe?
It is fully open source under GPL-2.0, built on Vanadium patches, and its releases can be verified with gh attestation verify. The README states that it only improves security and privacy where possible, and that GrapheneOS with Vanadium offers better protection because it also patches Android System WebView and hardens the OS.
Is there a Chromium browser for Android that supports extensions?
Titanium Browser for Android is one: a Chromium-based browser that supports extensions, including Manifest V2. Chrome Web Store extensions install after enabling Desktop site in the store menu, and unpacked extensions load through chrome://extensions with Developer mode on.
How do I install Titanium Browser for Android?
Download the APK from the GitHub Releases page, or install it from Google Play under the package id io.github.jqssun.helium. The README notes that you can update between GitHub and Google Play releases seamlessly.
Why does Discord Voice not work in Titanium Browser for Android?
The README states that WebRTC IPs are shielded by default, which can break WebRTC features such as Discord Voice. It suggests changing the policy under Settings, Privacy and security to Default public interface only or Default.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/jqssun-android-titanium-browser)