vulnerability
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
High
Summary
Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowing arbitrary code execution. The UDC, used for decoding Dolby Digital Plus (DD+) audio, is integrated into Android and other platforms. The exploit leverages a lack of size limits on the skip buffer, combined with an integer overflow, to overwrite a pointer, ultimately leading to code execution. The vulnerability has been patched as of January 5, 2026.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data