A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects, highlights significant security gaps in Android's 0-click attack surface and the slow pace of patching vulnerabilities. The vulnerability allows for code execution in a sandboxed context, and the slow response from Dolby and Pixel vendors meant that devices remained vulnerable for an extended period. The research underscores the need for improved vendor collaboration, proactive vulnerability analysis, and a more rigorous approach to 0-click exploit mitigation.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data