logo

Google Project Zero Reveals Zero-Click Exploit Chain for Pixel 10

ID: db8e41be-3075-5377-b52b-4bee8da1520e

STIX ID: report--db8e41be-3075-5377-b52b-4bee8da1520e

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: AnuPriya

...
...

Google Project Zero researchers disclosed a full zero-click exploit chain targeting Pixel 10 devices: a critical Dolby Unified Decoder (CVE-2025-54957) audio parsing flaw enables remote triggering via crafted DD+ audio, and a separate VPU driver mmap handler bug permits oversized mappings of physical memory to user space, yielding arbitrary kernel read/write and complete kernel control. The chain exploits the device’s automatic media processing and fixed kernel physical address to avoid KASLR, was developed into a working exploit by Project Zero researchers, and was patched by Google in the February Pixel security bulletin after a 71-day disclosure-to-fix window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.