vulnerability A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowing arbitrary code execution. The UDC, used for decoding Dolby Digital Plus (DD+) audio, is integrated… Google Project Zero · Jan 14, 2026 High CVE-2025-49415CVE-2025-54957CVE-2025-369340-clickbuffer overflowmemory leak