As cited
Copy frozen at (site build).
vulnerabilities
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Researchers demonstrated a zero-click exploit chain for the Google Pixel 10 that achieves root access through two vulnerabilities: an updated Dolby decoder exploit (CVE-2025-54957) and a critical flaw in the VPU driver that allows unmapped kernel memory access. The VPU driver's mmap handler fails to bound memory mappings to the hardware register region, enabling arbitrary kernel memory access and modification from userspace.
Why it matters: Pixel 10 users with December 2025 or earlier security patch levels are exposed to unauthenticated complete device compromise via network or local triggers, and device manufacturers and security teams need to prioritize patching the VPU driver vulnerability immediately as it represents a straightforward path to kernel code execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Researchers demonstrated a zero-click exploit chain for the Google Pixel 10 that achieves root access through two vulnerabilities: an updated Dolby decoder exploit (CVE-2025-54957) and a critical flaw in the VPU driver that allows unmapped kernel memory access. The VPU driver's mmap handler fails to bound memory mappings to the hardware register region, enabling arbitrary kernel memory access and modification from userspace.
Why it matters: Pixel 10 users with December 2025 or earlier security patch levels are exposed to unauthenticated complete device compromise via network or local triggers, and device manufacturers and security teams need to prioritize patching the VPU driver vulnerability immediately as it represents a straightforward path to kernel code execution.
- Source published
- First seen by Cybersecurity Tracker