The new Google Pixel 2 ships with a security module built using tamper-resistant hardware that protects your lock screen and your data against many sophisticated hardware attacks. Because it has its own dedicated RAM, its robust against many side-channel information leakage attacks. It loads its operating system and software directly from internal ROM and flash, and it controls all updates to it, so attackers cant directly tamper with its software to inject malicious code. Because the security module is designed so that nobody, including Google, can update the passcode verification logic to a weakened version without knowing your passcode first.”]
Source: https://security.googleblog.com/2017/11/lock-it-up-new-hardware-protections-for.html

