logo

The Pixel 9 Zero-Click Exploit Chain That Breaks the Kernel

ID: fad1d551-94ba-520f-ae3a-f40c60f3d94c

STIX ID: report--fad1d551-94ba-520f-ae3a-f40c60f3d94c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Project Zero published a detailed three-part analysis of a zero-click exploit chain targeting Google Pixel 9 devices: a Dolby Unified Decoder metadata memory-corruption (CVE-2025-54957) yields code execution in the mediacodec process, which is then escalated to kernel-level control via an AV1 driver flaw (CVE-2025-36934) related to /dev/bigwave. The researchers note the moderate development effort required, highlight delays in patch rollout (public disclosure Oct 15, 2025; Pixel patch in the Jan 5, 2026 security update), and advise users to install the January 2026 security updates and keep messaging/media-processing apps current.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.