A critical zero-click remote code execution (RCE) vulnerability has been discovered in the Dolby Unified Decoder, a widely used audio format processing component present in Android, iOS, and macOS devices. The flaw, tracked as CVE-2025-54957, is a high-severity out-of-bounds write issue that can be exploited by threat actors through maliciously crafted audio messages. According to Google Project Zero researchers Ivan Fratric and Natalie Silvanovich, the vulnerability arises from improper handling of evolution data within the decoder. Specifically, the decoder writes evolution information into a large, heap-like buffer, but a flaw in the length calculation due to integer wrap can result in overwriting later members of the struct, including critical pointers. This memory corruption can be triggered without any user interaction, making it a zero-click attack vector, particularly on Android devices. The vulnerability allows attackers to execute arbitrary code remotely, posing a significant risk to affected systems. Google has responded by releasing patches for ChromeOS to address the issue, demonstrating the cross-platform impact of the vulnerability. Microsoft has also included a fix for the flaw in its latest Patch Tuesday updates, indicating that Windows systems utilizing the Dolby decoder may also be at risk. The vulnerability's zero-click nature means that users could be compromised simply by receiving a malicious audio file, without needing to open or interact with it. Security researchers emphasize the importance of promptly applying available patches to mitigate the risk of exploitation. The discovery highlights the ongoing challenges in securing complex multimedia processing components, which are often integrated into a wide range of consumer and enterprise devices. The flaw's technical details, including the specific buffer overflow mechanism and the potential for pointer overwrites, underscore the sophistication required to both discover and exploit such vulnerabilities. The coordinated disclosure and rapid patching efforts by Google and Microsoft reflect the seriousness of the threat. Organizations are advised to review their exposure to the Dolby Unified Decoder and ensure all relevant updates are applied. The incident serves as a reminder of the critical need for robust security testing in third-party components embedded within operating systems and applications. Ongoing monitoring for exploitation attempts is recommended, as threat actors may attempt to reverse-engineer the patches to develop working exploits. The vulnerability's impact across multiple platforms increases its attractiveness to attackers, making timely remediation essential for both individual users and enterprises.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A security researcher publicly detailed a zero-click remote code execution vulnerability in the Dolby audio decoder, reporting that it could affect Android, iOS, and macOS devices. The available references indicate disclosure of the bug and its attack potential, but do not provide an earlier discovery or patch date.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.