threat-intel Bypassing Windows Administrator Protection Microsoft has introduced Administrator Protection in Windows 11 to replace UAC, aiming to create a more secure boundary for administrator privileges. However, research by Google Project Zero revealed nine separate vulner… Google Project Zero · Jan 26, 2026 High uacadministratorbypass
vulnerability A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects… Google Project Zero · Jan 14, 2026 High CVE-2025-54957CVE-2025-369340-clickaudiodriver
supply-chain A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing… Google Project Zero · Jan 14, 2026 Critical kernelsupply-chainarbitrary-read-write
vulnerability A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby Google Project Zero discovered a 0-click exploit chain targeting the Dolby Unified Decoder (UDC) within the Google Messages app on Pixel 9 devices. The vulnerability stems from a buffer overrun and a memory leak, allowin… Google Project Zero · Jan 14, 2026 High CVE-2025-49415CVE-2025-54957CVE-2025-369340-clickbuffer overflowmemory leak
vulnerability Welcome to the new Project Zero Blog Project Zero has revived older research to highlight the ongoing need for zero-day defenses. The blog post focuses on past exploitation techniques, specifically a 2016 article detailing race conditions in Windows path lo… Google Project Zero · Dec 16, 2025 Medium vulnerabilitywindowsexploitation