TL;DR

Google Project Zero reports a 0-click vulnerability in Dolby Unified Decoder used on many Android phones, enabling potential RCE attacks without user interaction.

What happened

['Dolby Unified Decoder found to be vulnerable', 'Automatic media decoding exposes security risk', 'CVE-2025-54957 impacts most Android devices']

Why it matters for ops

['Increased attack surface due to AI features', 'Media processing vulnerabilities allow RCE']

Mitigation

  • Update to latest security patches immediately
  • Disable automatic media decoding features if possible

Action items

  • Apply available security updates
  • Monitor systems for suspicious activity

Detection IOCs

  • Unusual network traffic from audio decoder processes
  • Unexpected process privilege escalation attempts

Source link

https://projectzero.google/2026/01/pixel-0-click-part-1.html