CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 572

As cited

Copy frozen at (site build).

vulnerabilities

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.

Why it matters: Pixel 9 users and device administrators should apply the January 2026 security updates, as this 0-click exploit chain can be triggered through decoding operations without user interaction, leading to complete device compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.

Why it matters: Pixel 9 users and device administrators should apply the January 2026 security updates, as this 0-click exploit chain can be triggered through decoding operations without user interaction, leading to complete device compromise.

VendorsGoogleLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary