Google Project Zero Details Pixel 10 Zero-Click Exploit Chain
ID: 4c6f4459-f0fe-5cdf-ae18-60a9237ea15f
STIX ID: report--4c6f4459-f0fe-5cdf-ae18-60a9237ea15f
Feed Name: GBHackers
Threat Score
Project Zero published a zero-click exploit chain for Pixel 10 that starts with a remote Dolby Unified Decoder RCE (CVE-2025-54957) delivered via crafted DD+ audio streams and chains to a vendor VPU driver mmap vulnerability that permits arbitrary physical memory mapping and full kernel read/write, enabling complete device compromise; Google patched the issues in the January–February 2026 updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
