Cybersecurity — 2026-05-15

Google Project Zero Publishes Pixel 10 Zero-Click Exploit Chain Details

BLUFRecurring shallow flaws in the same vendor driver lineage signal that Google's faster patching masks an unreformed development culture, leaving zero-click compromise of flagship Pixels readily achievable by capable adversaries.

Google Project Zero researcher Seth Jenkins published on May 13 technical details of a two-stage zero-click exploit chain for the Pixel 10. The first stage exploits CVE-2025-54957, a Dolby Unified Decoder flaw that triggers automatically when Google Messages processes an incoming audio message, with no interaction from the target. In a two-hour audit, Jenkins and Jann Horn found the Pixel 10's VPU kernel driver mmap handler calls remap_pfn_range with no size bounds, allowing a caller to map the full kernel image into userspace; Jenkins reported achieving arbitrary kernel read-write in five lines of code. Jenkins disclosed the VPU flaw on November 24, 2025, and Google patched it 71 days later in the February 2026 Pixel security bulletin.

Analysis
The VPU driver flaw is a structural recurrence: the same team whose BigWave driver enabled root compromise on the Pixel 9 shipped an equivalent flaw in the Pixel 10. Five lines of code achieved arbitrary kernel read-write, per Project Zero's sole disclosure. Pixel's fixed kernel physical address eliminates KASLR, removing offset uncertainty that would otherwise force memory scanning. The Dolby UDC case establishes audio transcription pipelines as zero-click entry points that expand as Android absorbs AI media processing. The Tensor G5 driver stack may instead have been finalized before BigWave audit findings could reach the team, rather than institutional resistance. Google's 71-day turnaround marks genuine remediation progress, but patch velocity and secure development practice are not advancing in parallel.
4 sources
  1. Pixel 10 Zero-Click Exploit Chain Analysis - Google Project Zero
  2. A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens - Google Project Zero
  3. Google's Security Team Built a Zero-Click Root Exploit for the Pixel 10 - Cyber Kendra
  4. Google Project Zero Reveals Zero-Click Exploit Chain for Pixel 10 - CyberPress

View in full brief →

UNCLASSIFIED // OPEN SOURCE