Bringing Rust to the Pixel Baseband

2026-04-23T01:23:42Z816b65a0934098890807f039df09ab45b14cfd77b7ef85ae9357e656484156f7
Android 17DBSCDNS parserIPILLM securityMerkle Tree CertificatesPLANTSPQCVRPbasebandcellular modemcertificate transparency (CT)chromecookie theftdevice-bound-session-credentialsindirect prompt injectionmemory-safetymodem firmwarepost-quantum cryptographyproject zeroquantum-safe HTTPSremote code executionrustsession hijackingvulnerability rewards program

What happened

Collection of Google Security Blog posts (Apr 2026) covering multiple defensive advances: Pixel baseband hardening by integrating a memory-safe Rust DNS parser into modem firmware to reduce memory-safety vulnerabilities; rollout of Device Bound Session Credentials (DBSC) to Chrome (Windows in Chrome 146, macOS upcoming) to prevent stolen cookies from enabling session takeover; Google Workspace mitigations and continuous defenses against indirect prompt injection (IPI) targeting LLM-based apps; a VRP (Vulnerability Rewards Program) 2025 year-in-review; Android’s phased adoption of Post‑Quantum‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
816b65a0934098890807f039df09ab45b14cfd77b7ef85ae9357e656484156f7
Enrichment time
2026-04-23T01:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.