news.mlab.sh
Back to the feed
threat-intel

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

CriticalCVSS 9.8
Summary

Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` function, which allows userspace to map a large portion of the kernel's memory region into userland. This was achieved with just 5 lines of code and required less than a day to exploit, highlighting a significant weakness in Android driver security. The vulnerability was patched 71 days after initial reporting, a notable improvement over previous driver vulnerabilities.

Read the full article at Google Project Zero

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.