Bringing Rust to the Pixel Baseband

2026-04-18T13:23:38Z5e4378c4804076d5c6154656d85560c260485852e7c50e7adfc3fd2c9644852a
Android 17ChromeDBSCDNS parserIPILLM securityMTCMerkle Tree CertificatesPLANTS working group','Certificate Transparency','scam-protectorPQCPixel 10RustVRPVulnerability Rewards ProgramWorkspacebasebandcookiesdevice-bound session credentialsindirect prompt injectioninfostealermemory-safetymodempost-quantum cryptographyquantum-safe HTTPSsession theft

What happened

The Google Security Blog batch highlights multiple defensive initiatives across Google products: Pixel 10 integrates a memory-safe Rust DNS parser into the cellular modem firmware to reduce classes of memory-safety bugs in a high-risk attack surface; Chrome is rolling out Device Bound Session Credentials (DBSC) (publicly available on Windows in Chrome 146, coming to macOS) to proactively prevent cookie/session theft by making exfiltrated cookies unusable; Google Workspace continues an ongoing program of mitigations against indirect prompt injection (IPI) in LLM-powered apps; the Vulnerability

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
5e4378c4804076d5c6154656d85560c260485852e7c50e7adfc3fd2c9644852a
Enrichment time
2026-04-18T13:23:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.