Bringing Rust to the Pixel Baseband
2026-04-20T19:23:41Z•e220457e78c00b11a0fa4ebdff9327cbcf25b364bbab7d0022ea3a506dd98b43
AndroidAndroid-17DBSCDNSLLM-securityMerkle-tree-certificatesPQCPixelRCS-spamTLSbasebandbug-bountycertificate-transparencycookiesdevice-bound-session-credentialsindirect-prompt-injectioninfostealermemory-safetymodempost-quantum-cryptographyquantum-saferustscam-protectionsession-theftvulnerability-rewards-program
What happened
A set of Google Security Blog posts covering multiple defensive initiatives: Pixel baseband firmware hardening by integrating a memory-safe Rust DNS parser to reduce modem memory-safety vulnerabilities; Device Bound Session Credentials (DBSC) entering public availability on Windows (Chrome 146) and coming to macOS to prevent cookie-based session theft by infostealer malware; ongoing mitigations and detection strategy improvements for indirect prompt injection (IPI) against LLM-backed apps like Workspace/Gemini; the Vulnerability Rewards Program (VRP) 2025 year-in-review; Android’s phased roll‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- e220457e78c00b11a0fa4ebdff9327cbcf25b364bbab7d0022ea3a506dd98b43
- Enrichment time
- 2026-04-20T19:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.