Google fixes critical Dolby Decoder bug in Android January update
ID: b6302aef-f2ee-5ab5-812e-f6de8752cf73
STIX ID: report--b6302aef-f2ee-5ab5-812e-f6de8752cf73
Feed Name: Security Affairs
Android's January 2026 security update addresses CVE-2025-54957, a critical Dolby Digital Plus (DD+) decoder vulnerability (UDC v4.5–v4.13) discovered by Google Project Zero. The bug, caused by an integer overflow leading to an out-of-bounds write that can overwrite pointers, poses a 0‑click risk on Android as audio is decoded automatically; Google rolled out fixes for Pixel devices in December 2025 and for all Android devices in January 2026. While researchers warn the flaw could be chained with other issues to increase impact, the report does not present confirmed evidence of active widespread exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
