Zero-Click Exploit Chain Discovered Targeting Google Pixel 9 Devices
ID: 7a839b4c-d96e-506c-bf06-29f873f0d280
STIX ID: report--7a839b4c-d96e-506c-bf06-29f873f0d280
Feed Name: GBHackers
Google Project Zero disclosed a complete zero‑click exploit chain impacting Pixel 9 devices that chains an EMDF integer overflow in the Dolby Unified Decoder (CVE-2025-54957) with a kernel driver privilege escalation (CVE-2025-36934) and a third vector to achieve arbitrary code execution in the mediacodec sandbox and subsequent system‑level escalation; the advisory details how malformed audio bitstreams can trigger allocator integer wrap leading to controlled out‑of‑bounds writes and information leaks, and notes that all three vulnerabilities were patched as of 2026‑01‑05 with a multi‑part technical writeup forthcoming.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
