Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Mobile device attack surface evolution demonstrates zero-interaction compromise paths despite security model hardening in latest generation hardware.

Summary written by editorial AI · Source link below

Filed by Project Zero1 min readCVE-2025-54957Read at source ↗
CVSS9.8criticalCVE-2025-54957

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10. Updating the Dolby Exploit Altering our exploit for CVE-2025-54957 was fairly straightforward. The m

Continue at the source
Read the full report at Project Zero

External link — opens at Project Zero in a new tab.

§
Continue with

More from the Research Desk