Google Project Zero Publishes Pixel 10 Zero-Click Exploit Chain Details
The VPU driver flaw is a structural recurrence: the same team whose BigWave driver enabled root compromise on the Pixel 9 shipped an equivalent flaw in the Pixel 10. Five lines of code achieved arbitrary kernel read-write, per Project Zero's sole disclosure. Pixel's fixed kernel physical address eliminates KASLR, removing offset uncertainty that would otherwise force memory scanning. The Dolby UDC case establishes audio transcription pipelines as zero-click entry points that expand as Android absorbs AI media processing. The Tensor G5 driver stack may instead have been finalized before BigWave audit findings could reach the team, rather than institutional resistance. Google's 71-day turnaround marks genuine remediation progress, but patch velocity and secure development practice are not advancing in parallel.
4 sources
- Pixel 10 Zero-Click Exploit Chain Analysis -
Google Project Zero - A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens -
Google Project Zero - Google's Security Team Built a Zero-Click Root Exploit for the Pixel 10 -
Cyber Kendra - Google Project Zero Reveals Zero-Click Exploit Chain for Pixel 10 -
CyberPress