Bringing Rust to the Pixel Baseband
2026-04-13T13:23:41Z•1d53d76f30609c2f6a2e4fac3858c726b3da325b9e0f976de7d32768944c67d2
ChromeDBSCDNS parserDevice Bound Session CredentialsGenAILLM securityPQC','Android 17','Android security','quantum-safe HTTPS','Merk"PixelRustVRPVulnerability Rewards ProgramWorkspacebasebandbrowser securitybug bountycookie protectionindirect prompt injectioninfostealermalwarememory-safetymobile securitymodem securitypost-quantum cryptographyprompt injectionsession theft
What happened
This collection of Google security posts describes multiple proactive defenses and platform hardening efforts: Pixel modem firmware hardening by integrating a memory-safe Rust DNS parser to reduce baseband memory‑safety vulnerabilities; Device Bound Session Credentials (DBSC) rolling to public availability (Chrome 146 on Windows, coming to macOS) to prevent cookie-based session theft by malware; ongoing mitigations and defenses against indirect prompt injection in Workspace/GenAI; a Vulnerability Rewards Program (VRP) 2025 year-in-review; Android’s staged rollout of Post-Quantum Cryptography (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 1d53d76f30609c2f6a2e4fac3858c726b3da325b9e0f976de7d32768944c67d2
- Enrichment time
- 2026-04-13T13:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.