threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` function, which allows a user-space process to map a large region of physical memory into its address space… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability
vulnerability A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects… Google Project Zero · Jan 14, 2026 High CVE-2025-54957CVE-2025-369340-clickaudiodriver
vulnerability A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowin… Google Project Zero · Jan 14, 2026 High CVE-2025-49415CVE-2025-54957CVE-2025-369340-clickbuffer overflowmemory leak