An AI-made picture now carries a Google-issued credential that says a Pixel camera captured it and that nothing has touched it since. Researcher David Buchanan published the fake on August 25. He also put up a YouTube video, and YouTube showed a "captured with a camera" label on it. The label was gone later that day. Buchanan says the removal looks manual.
Pixel 10 phones attach a credential to every photo the Pixel Camera app makes. It names Pixel Camera as the signer and lets anyone check whether the file changed after signing. Google calls this Content Credentials and shipped it with the Pixel 10 in August 2025, then explained the design that September. It said the camera app hit Assurance Level 2, the highest rating the C2PA conformance program currently defines. That is the rating carried by the app whose credentials Buchanan forged.
How you sign a fake
The key that signs a Pixel photo lives in a small security chip. Root alone cannot pull it out. It does not have to. With root, the top level of control over an Android phone, you can ask the protected key to sign a credential for any file you like.
One road to root leaves a mark. Unlocking the bootloader wipes the phone and changes what it reports about itself, and Android Key Attestation catches that, so Pixel Camera never gets its key. Rooting through a software bug touches neither the bootloader nor the patch level that attestation looks at. The phone still looks locked and fully updated, so the key arrives as usual.
Buchanan signed the demo itself with a hardware fault-injection attack, a continuation of research he has already published. He is holding the rest of those details for a later post. The route he does document is the one anyone can repeat.
It runs on GhostLock, a Linux flaw introduced in 2011 that can give an unprivileged local user root on a vulnerable kernel. Someone else has already packaged it as a one-click rooting tool, Root My Pixel. Buchanan says a build from source covers current updates on most Pixels, though he only tested a Pixel 8a and a 9a himself.
He also says Meta patched GhostLock on Quest headsets in early August, apparently because people were using it to cheat at VR games, and that Google still has not patched it on Pixel.
How the Pixel photo signature was forged
Won't fix, and a $7,500 payout
Google closed the report as "Won't fix (infeasible)" and paid Buchanan $7,500 anyway. "While hardware glitching and side channel attacks are out of scope for our bug bounty program, our security team found your findings valuable, and the data you provided will help us improve future iterations of the product," the reply said. That scope is Buchanan's complaint. The route he finds most obvious is the one the program normally leaves out.
He argues a real fix would move the whole image pipeline, AI processing and all, into a strongly protected environment. Even that leaves the oldest trick alive. Point the phone at a screen with the fake on it.
Pixel is also not the only phone affected. The other Android camera apps Buchanan looked at lean on the same attestation, or on Play Integrity, or on both. So a forger does not have to attack a Pixel at all. A cheaper vulnerable phone running one of those apps would do.
GhostLock kernel flaw disclosure
What the badge is worth
While preparing the demo, Buchanan says he found a second hole that exposes a Pixel Camera signing key outright. He says he reported it on August 23 and that Google appeared to patch it the next day. The C2PA rules do describe a revocation check, but the live lookup is a should, not a must. Buchanan says most tools skip it, so a stolen key keeps verifying after it is cancelled.
A Content Credential still proves one real thing. It proves the file has not changed since it was signed. It does not prove a camera sensor ever saw the scene, and Buchanan's fake is the demonstration.



