Hardening cellular basebands in Android
ID: 7d40e714-df7d-550b-b657-0ac988b58aa6
STIX ID: report--7d40e714-df7d-550b-b657-0ac988b58aa6
Feed Name: Google Online Security Blog
Google describes a defense-in-depth strategy for hardening cellular baseband firmware by enabling Clang UBSan sanitizers—Integer Overflow (IntSan) and Bounds (BoundSan)—in bare‑metal code, with guidance on diagnostics vs trapping modes, staged deployment (detect/fix, measure/optimize, pre‑production soak), targeted application to high-risk parsers and protocol stacks, managing performance overhead, leveraging modern toolchains, selectively disabling 2G where feasible, and progressively adopting memory-safe Rust to further reduce vulnerability classes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
