Google Project Zero details a sophisticated 0-click exploit chain targeting the Pixel 9 through a vulnerability (CVE-2025-54957) in the Dolby Unified Decoder. The exploit leverages an integer overflow in EMDF payload processing to achieve arbitrary code execution in the mediacodec context. The attack chain involves manipulating

54m read timeFrom projectzero.google
Post cover image
Table of contents
The Dolby Unified DecoderThe BugDecoder Memory LayoutWrite what where?Extending the evo heapControlling PCNon-contiguous OverwritesOverwriting payload_extraCalling Controllable FunctionsWhat’s the plan, (Seth and) Jann?The ExploitHow reliable is this exploit?Reflections on MitigationsThe Next Step

Sort: