logo

Google fixes critical Dolby Decoder bug in Android January update

ID: b6302aef-f2ee-5ab5-812e-f6de8752cf73

STIX ID: report--b6302aef-f2ee-5ab5-812e-f6de8752cf73

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Android's January 2026 security update addresses CVE-2025-54957, a critical Dolby Digital Plus (DD+) decoder vulnerability (UDC v4.5–v4.13) discovered by Google Project Zero. The bug, caused by an integer overflow leading to an out-of-bounds write that can overwrite pointers, poses a 0‑click risk on Android as audio is decoded automatically; Google rolled out fixes for Pixel devices in December 2025 and for all Android devices in January 2026. While researchers warn the flaw could be chained with other issues to increase impact, the report does not present confirmed evidence of active widespread exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.