Bringing Rust to the Pixel Baseband

2026-04-14T01:23:46Z955ce1e496b0354a11a35d1d50b9f5aa66f19e1879d2484b1f3b50aad8a054e5
Android 17DBSCPQCVRP 2025android scam protectioncertificate transparencychrome 146cookie theftdevice-bound session credentialsdns parsergenai securityindirect prompt injectionmemory-safetymerkle tree certificatesmodem securitypixel basebandpost-quantum cryptographyquantum-safe HTTPSrcs spamrustsession hijacking mitigationvulnerability rewards programworkspace security

What happened

This collection of Google security blog posts (April 2026) covers multiple product security advances and program updates. Key items: Pixel team integrated a memory-safe Rust DNS parser into modem firmware to reduce memory-safety vulnerabilities in the baseband; Chrome announced Device Bound Session Credentials (DBSC) reaching public availability on Windows (Chrome 146) and expansion to macOS to prevent stolen cookies from being usable by attackers; Google Workspace described ongoing mitigations against indirect prompt injection (IPI) in LLM-based apps; the Vulnerability Rewards Program (VRP) �

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
955ce1e496b0354a11a35d1d50b9f5aa66f19e1879d2484b1f3b50aad8a054e5
Enrichment time
2026-04-14T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.