threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` function, which allows a user-space process to map a large region of physical memory into its address space… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability