Bringing Rust to the Pixel Baseband

2026-04-16T19:23:46Z3d5a62ddcf70ae4d941e0826af54a40f47aba69087dfa38337a485c4075a5add
android-17basebandcertificate-transparencychromecookie-theftdbscdevice-bound-session-credentialsdns-parserfirmware-hardeningindirect-prompt-injectionllm-securitymemory-safetymerkle-tree-certificatesmobile-securitymodemplants-ietfpost-quantum-cryptographypqcprompt-injectionquantum-safe-tlsrustscam-protectionsession-securityvrpvulnerability-rewards

What happened

Collection of Google Security Blog posts (Feb–Apr 2026) describing multiple platform security initiatives: integrating a memory-safe Rust DNS parser into Pixel modem firmware to reduce baseband memory-safety vulnerabilities; public availability rollout of Device Bound Session Credentials (DBSC) in Chrome to mitigate cookie/session theft by infostealers; ongoing mitigations and detection strategies against indirect prompt injection (IPI) for Google Workspace/LLM apps; a 2025 VRP (Vulnerability Rewards Program) year-in-review; Android’s multi-year migration to Post‑Quantum Cryptography with PQC/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
3d5a62ddcf70ae4d941e0826af54a40f47aba69087dfa38337a485c4075a5add
Enrichment time
2026-04-16T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.