Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices
ID: b8749294-d2f3-510c-b379-f1721cb2b8bd
STIX ID: report--b8749294-d2f3-510c-b379-f1721cb2b8bd
Feed Name: cybersecurityNews.com
Project Zero disclosed a zero-click exploit chain targeting Google Pixel 10 devices that combines a Dolby Media Framework remote code execution flaw with a newly introduced VPU (/dev/vpu) driver mmap bug that fails to validate mapping sizes. The VPU driver flaw exposes large regions of physical memory, allowing attackers to locate and overwrite kernel structures to gain arbitrary kernel read/write and escalate to root; the issue was reported in November 2025 and patched in the February 2026 Android security update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
