- An AI-made photo carries a real Google credential saying a Pixel camera shot it.
- A rooted phone can ask the camera app's protected key to sign any file.
- Google paid a $7,500 bug bounty but marked the flaw won't fix.
- Other Android camera apps with Content Credentials have the same weakness.
- The credential only proves a file wasn't edited, not that a camera took it.
Security researcher David Buchanan made an AI-generated picture carry a real Google Content Credential, the signature Pixel 10 phones attach to real camera photos. The credential says a Pixel Camera app took the picture and nothing has changed since. He also posted a YouTube video that briefly showed a captured-with-a-camera label. Buchanan says the label vanished later that day, and the removal looked manual.
Google built Content Credentials into the Pixel 10 line, and the Pixel Camera app names itself as the signer on every photo it takes. Google says the app reached Assurance Level 2, the highest rating the C2PA industry program currently defines. That is the same rating carried by the credential Buchanan forged.
Google Pixel C2PA Content Credentials
The signing key sits inside a security chip, and root alone can't pull it out, but it can ask the chip to sign a credential for any file. Unlocking a phone's bootloader the normal way leaves a mark that Google's system catches, so it won't issue a key. Rooting through a software bug leaves no mark, so the phone looks locked and updated and gets a key as usual.
Buchanan says he signed his demo using a hardware attack he hasn't detailed yet. The method he did publish uses GhostLock, a Linux bug that has existed since 2011 and lets a normal user gain root. A separate tool called Root My Pixel packages the exploit, and building it from source covers most current Pixel phones, though Buchanan only tested a Pixel 8a and a 9a.
Buchanan says Meta patched GhostLock on its Quest headsets in early August to stop VR game cheating, but Google has not patched it on Pixel phones. Google closed his report as won't fix, calling the issue infeasible, and paid him a $7,500 bounty anyway. Google told him hardware glitching attacks are out of scope for its bug bounty program, though its security team called the findings valuable.
Buchanan says that gap means the most obvious attack on Content Credentials falls outside Google's bug bounty program. He argues a real fix would need the whole photo pipeline running inside a protected chip, and even that wouldn't stop someone from pointing a camera at a screen. Other Android camera apps with Content Credentials rely on the same security, so a forger just needs any cheap vulnerable Android phone.
While preparing his demo, Buchanan found a separate bug that exposed a Pixel Camera signing key. He reported it on August 23 and Google patched it the next day. He says most verification tools skip checking whether a key was revoked, so a stolen key keeps working after Google cancels it. A Content Credential only proves a file hasn't changed since signing, not that a camera took the picture.




