CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 567

As cited

Copy frozen at (site build).

vulnerabilities

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Researchers demonstrated a zero-click exploit chain for the Google Pixel 10 that achieves root access through two vulnerabilities: an updated Dolby decoder exploit (CVE-2025-54957) and a critical flaw in the VPU driver that allows unmapped kernel memory access. The VPU driver's mmap handler fails to bound memory mappings to the hardware register region, enabling arbitrary kernel memory access and modification from userspace.

Why it matters: Pixel 10 users with December 2025 or earlier security patch levels are exposed to unauthenticated complete device compromise via network or local triggers, and device manufacturers and security teams need to prioritize patching the VPU driver vulnerability immediately as it represents a straightforward path to kernel code execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Researchers demonstrated a zero-click exploit chain for the Google Pixel 10 that achieves root access through two vulnerabilities: an updated Dolby decoder exploit (CVE-2025-54957) and a critical flaw in the VPU driver that allows unmapped kernel memory access. The VPU driver's mmap handler fails to bound memory mappings to the hardware register region, enabling arbitrary kernel memory access and modification from userspace.

Why it matters: Pixel 10 users with December 2025 or earlier security patch levels are exposed to unauthenticated complete device compromise via network or local triggers, and device manufacturers and security teams need to prioritize patching the VPU driver vulnerability immediately as it represents a straightforward path to kernel code execution.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary