Bringing Rust to the Pixel Baseband
2026-04-14T01:23:46Z•955ce1e496b0354a11a35d1d50b9f5aa66f19e1879d2484b1f3b50aad8a054e5
Android 17DBSCPQCVRP 2025android scam protectioncertificate transparencychrome 146cookie theftdevice-bound session credentialsdns parsergenai securityindirect prompt injectionmemory-safetymerkle tree certificatesmodem securitypixel basebandpost-quantum cryptographyquantum-safe HTTPSrcs spamrustsession hijacking mitigationvulnerability rewards programworkspace security
What happened
This collection of Google security blog posts (April 2026) covers multiple product security advances and program updates. Key items: Pixel team integrated a memory-safe Rust DNS parser into modem firmware to reduce memory-safety vulnerabilities in the baseband; Chrome announced Device Bound Session Credentials (DBSC) reaching public availability on Windows (Chrome 146) and expansion to macOS to prevent stolen cookies from being usable by attackers; Google Workspace described ongoing mitigations against indirect prompt injection (IPI) in LLM-based apps; the Vulnerability Rewards Program (VRP) �
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 955ce1e496b0354a11a35d1d50b9f5aa66f19e1879d2484b1f3b50aad8a054e5
- Enrichment time
- 2026-04-14T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.