news.mlab.sh
Back to the feed
vulnerability

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

High
Summary

Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowing arbitrary code execution. The UDC, used for decoding Dolby Digital Plus (DD+) audio, is integrated into Android and other platforms. The exploit leverages a lack of size limits on the skip buffer, combined with an integer overflow, to overwrite a pointer, ultimately leading to code execution. The vulnerability has been patched as of January 5, 2026.

Read the full article at Google Project Zero

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.