Hacker News
Google Project Zero: Zero-Click Exploit Chain for Pixel 10 — 'Holy Grail' Kernel Vulnerability Needed 5 Lines of Code
Project Zero researchers chained CVE-2025-54957 (Dolby audio decoder flaw) with a VPU kernel driver bug to achieve full Pixel 10 root with zero user interaction — incoming audio messages are transcribed before the user opens them, making this a zero-click attack surface. Researcher Seth Jenkins called the kernel bug 'the Holy Grail of kernel vulnerabilities,' noting the full exploit required 'less than a day of effort' and only '5 lines of code' for arbitrary kernel read-write. Patched in the February 2026 security bulletin.
↳ Follow the thread