As cited
Copy frozen at (site build).
vulnerabilities
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.
Why it matters: Pixel 9 users and device administrators should apply the January 2026 security updates, as this 0-click exploit chain can be triggered through decoding operations without user interaction, leading to complete device compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.
Why it matters: Pixel 9 users and device administrators should apply the January 2026 security updates, as this 0-click exploit chain can be triggered through decoding operations without user interaction, leading to complete device compromise.
- Source published
- First seen by Cybersecurity Tracker