Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Google Adds Rust DNS Parser to Pixel Phones for Better Security

The parser is meant to mitigate the entire class of memory safety bugs in the low-level environment.

Pixel 10 security

As part of its ongoing efforts to enhance the security of Pixel phones, Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware.

The move builds on previously announced deployment of Rust in low-level firmware codebases to eliminate memory safety issues that have historically plagued legacy C and C++ code in both Android and Chrome.

According to Google, attackers have shown an increased interest in targeting the cellular modem in recent years, and Pixel’s modem contains a large amount of executable code, creating a complex and remote attack surface.

“The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying the foundation for broader adoption of memory-safe code in other areas,” Google says.

Mostly associated with internet browsing, the DNS protocol plays a significant role in modern cellular technology and communications, with operations such as call forwarding relying on DNS services nowadays.

“DNS is a complex protocol and requires parsing of untrusted data, which can lead to vulnerabilities, particularly when implemented in a memory-unsafe language. Implementing the DNS parser in Rust offers value by decreasing the attack surfaces associated with memory unsafety,” Google explains.

Advertisement. Scroll to continue reading.

The internet giant chose the hickory-proto library for the DNS implementation, modified it for bare metal and embedded use, compiled the necessary Rust crates for its use, eliminated performance issues, and then implemented the necessary DNS responding parsing function API.

The Pixel 10 series devices, Google notes, are the first products to integrate the memory-safe language into the modem, thus marking a significant moment in advancing the series’ security.

“While replacing one piece of risky attack surface is itself valuable, this project lays the foundation for future integration of memory-safe parsers and code into the cellular baseband, ensuring the baseband’s security posture will continue to improve as development continues,” the company says.

Related: Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users

Related: Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

Related: Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

Related: Severe StrongBox Vulnerability Patched in Android

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.