logo

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

ID: b8749294-d2f3-510c-b379-f1721cb2b8bd

STIX ID: report--b8749294-d2f3-510c-b379-f1721cb2b8bd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Abinaya

...
...

Project Zero disclosed a zero-click exploit chain targeting Google Pixel 10 devices that combines a Dolby Media Framework remote code execution flaw with a newly introduced VPU (/dev/vpu) driver mmap bug that fails to validate mapping sizes. The VPU driver flaw exposes large regions of physical memory, allowing attackers to locate and overwrite kernel structures to gain arbitrary kernel read/write and escalate to root; the issue was reported in November 2025 and patched in the February 2026 Android security update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.