Fetching from the wire…
Security2026-08-26 · source-backed
David Buchanan got root on fully-patched Pixels two ways, electromagnetic fault injection flipping page table entry bits, and the public Root My Pixel exploit for CVE-2026-43499. He then impersonated the Pixel Camera app and had StrongBox sign arbitrary content with its C2PA credentials, never extracting key material from the secure element. That defeats the highest C2PA security rating and every Android camera app relying on Key Attestation or Play Integrity. His conclusion is blunt: a C2PA signature on an Android photo is not evidence of capture.
Each link below shares sources, entities, or timing with this story.
Claude uses C2PA / Shared entity: C2PA / Earlier coverage
Linked by a graph relationship (Claude uses C2PA); both cover C2PA; earlier C2PA coverage from 2026-08-13.
Linked by a graph relationship (Claude uses C2PA); both cover C2PA; earlier C2PA coverage from 2026-08-11.
Gemini uses C2PA / Shared entity: C2PA / Earlier coverage
Linked by a graph relationship (Gemini uses C2PA); both cover C2PA; earlier C2PA coverage from 2026-08-15.
Gemini uses C2PA / Shared entity: CVE / Earlier coverage / Tension
Linked by a graph relationship (Gemini uses C2PA); both cover CVE; earlier CVE coverage from 2026-07-23.
Claude uses C2PA / Shared entity: CVE / Earlier coverage / Tension
Linked by a graph relationship (Claude uses C2PA); both cover CVE; earlier CVE coverage from 2026-03-20.
Claude uses C2PA
Linked by a graph relationship (Claude uses C2PA).
Claude uses C2PA / Shared entity: CVE / Earlier coverage
Linked by a graph relationship (Claude uses C2PA); both cover CVE; earlier CVE coverage from 2026-08-09.
Claude uses C2PA
Linked by a graph relationship (Claude uses C2PA).