supply-chain A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing and allows for arbitrary read/write access to kernel memory, facilitated by a combination of careful… Google Project Zero · Jan 14, 2026 Critical kernelsupply-chainarbitrary-read-write