Bringing Rust to the Pixel Baseband
2026-04-11T13:23:42Z•e8f42967937dd864b5ef6f8378dbd06bede04eab953fe9d19ee7ba9ef0ca35a5
DBSCIPIPLANTSProject Zeroandroid-17basebandchromecookie-theftdevice-bound-session-credentialsdns-parserfirmware-hardeninggenai-securityindirect-prompt-injectioninfostealermemory-safetymerkle-tree-certificatesmodempixelpost-quantum-cryptographypqcremote-code-executionrustscam-protection','vulnerability-rewards-programsession-thefttls
What happened
This collection of Google security posts covers multiple platform- and product-level security initiatives: Google integrated a memory-safe Rust DNS parser into Pixel modem firmware to reduce memory-safety vulnerabilities in a high-risk baseband (motivated by prior Project Zero remote RCE findings). Chrome rolled out Device Bound Session Credentials (DBSC) to prevent stolen browser cookies from being reused by infostealer malware (Windows available in Chrome 146, macOS coming). Google Workspace teams described ongoing defenses against indirect prompt injection (IPI) targeting complex LLM apps.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- e8f42967937dd864b5ef6f8378dbd06bede04eab953fe9d19ee7ba9ef0ca35a5
- Enrichment time
- 2026-04-11T13:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.