The Pixel 9 Zero-Click Exploit Chain That Breaks the Kernel
ID: fad1d551-94ba-520f-ae3a-f40c60f3d94c
STIX ID: report--fad1d551-94ba-520f-ae3a-f40c60f3d94c
Feed Name: securityonline.info
Project Zero published a detailed three-part analysis of a zero-click exploit chain targeting Google Pixel 9 devices: a Dolby Unified Decoder metadata memory-corruption (CVE-2025-54957) yields code execution in the mediacodec process, which is then escalated to kernel-level control via an AV1 driver flaw (CVE-2025-36934) related to /dev/bigwave. The researchers note the moderate development effort required, highlight delays in patch rollout (public disclosure Oct 15, 2025; Pixel patch in the Jan 5, 2026 security update), and advise users to install the January 2026 security updates and keep messaging/media-processing apps current.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
