← Back
VulnerabilityGoogle Project Zero·7 months ago

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

Google Project Zero researchers identified systemic vulnerabilities in Android's security posture through a 0-click exploit chain targeting Pixel 9, revealing that attackers can achieve kernel-level compromise with just two software bugs and limited person-weeks of effort. The analysis exposes critical gaps including unnecessary codecs in the attack surface (like Dolby UDC), disabled security mitigations (kASLR, seccomp policies, and MTE), weak driver security, and slow patching timelines—with the Dolby UDC vulnerability remaining unfixed on Pixel devices for 82 days after public disclosure. Project Zero recommends Android vendors conduct rigorous 0-click attack surface analysis, enforce existing security features consistently, prioritize kernel bugs in exploit chains, rewrite drivers in memory-safe languages like Rust, and accelerate patch delivery through mechanisms like APEX.

Read full article at Google Project Zero

Related Articles

VulnerabilityCyberScoop·4 hours ago

Three 10.0 security flaws fixed across Ubiquiti’s UniFi line

Ubiquiti has patched three critical security vulnerabilities rated 10.0 across its UniFi product line as part of a larger disclosure addressing 22 total flaws. Nearly all of the disclosed vulnerabilities were rated critical, with severity scores of 9.0 or higher.

VulnerabilityMalwarebytes Labs·9 hours ago

Update Chrome before you browse again

Chrome's latest update addresses 327 security vulnerabilities, with some posing immediate risk to users through malicious websites. Security professionals should prioritize deploying this update across their environments to close exploitation vectors that require no user interaction beyond visiting a compromised site.

VulnerabilityTenable·10 hours ago

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable and SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored and criminal threat actors independently converge on the same edge infrastructure vendors, with 79% vendor-level overlap despite minimal CVE-level overlap across two independent datasets. Twelve vulnerabilities show confirmed multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware operators, demonstrating that the shared attack surface is the persistent exploitation target rather than any single adversary category. High-priority edge device CVEs face a statistically significant 24-day remediation delay compared to other vulnerabilities, with F5 showing the broadest exposure (54% of monitored customers) and Citrix showing the slowest patching timelines (461 days median), creating extended windows of opportunity for attackers across all threat actor categories.

VulnerabilitySentinelOne Labs·10 hours ago

Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter

A joint study from Tenable and SentinelOne examining two independent datasets reveals that both state-sponsored and criminal threat actors are targeting the same vulnerable edge infrastructure. The research highlights a concerning convergence where different adversary motivations lead to exploitation of perimeter defenses, suggesting organizations face multifaceted threats at their network boundaries.