Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

Pixel 9 sandbox escape demonstrates kernel driver exploitation from constrained mediacodec contexts in Android.

Summary written by editorial AI · Source link below

Filed by Project Zero1 min readRead at source ↗

With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible f

Continue at the source
Read the full report at Project Zero

External link — opens at Project Zero in a new tab.

§
Continue with

More from the Research Desk