news.mlab.sh
1 result
supply-chain

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A Google Project Zero researcher discovered a 0-click exploit chain targeting the Pixel 9, leveraging a BigWave hardware accelerator and a vulnerability in the mediacodec SELinux context. The exploit bypasses sandboxing and allows for arbitrary read/write access to kernel memory, facilitated by a combination of careful…

Google Project Zero · Jan 14, 2026 Critical