Google Project Zero disclosed a zero-click exploit chain for unpatched Pixel 10 devices that achieved full root compromise by combining a Dolby Media Framework remote code execution path with a privilege-escalation flaw in the Tensor G5 /dev/vpu driver. The chain adapted an earlier Pixel 9 technique built around CVE-2025-54957, but required changes for Pixel 10, including a different approach to bypass protections such as Return Address Pointer Authentication by targeting dap_cpdp_init instead of the older __stack_chk_fail overwrite method.
The local privilege-escalation bug was found in the Chips&Media Wave677DV VPU driver’s mmap handler, which failed to properly limit mappings to the MMIO register region and allowed userspace to map arbitrary physical memory, including kernel memory, through remap_pfn_range. Researchers said the flaw enabled arbitrary kernel read/write and kernel code execution because Pixel devices exposed the kernel at a predictable physical address. Google received the report on 2025-11-24, rated it High severity under Android VRP, and patched it 71 days later in the February Pixel security bulletin, while the disclosure renewed criticism of recurring shallow security flaws in Android drivers tied to the same developers behind earlier BigWave issues.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On May 1, 2026, Google Project Zero published technical details showing how a zero-click exploit chain could compromise unpatched Pixel 10 devices and escalate privileges to root. The disclosure described the adapted Dolby exploit, the new VPU driver flaw, and the security implications for Android driver development.
Google fixed the reported /dev/vpu driver vulnerability 71 days after disclosure in the February 2026 Pixel/Android security bulletin. The patch closed the privilege-escalation path used in the Pixel 10 zero-click-to-root chain.
After receiving the report, Google classified the Pixel 10 /dev/vpu driver vulnerability as a High-severity issue under Android VRP. This reflected the seriousness of the bug's impact on privilege escalation to root.
On November 24, 2025, researchers reported a severe vulnerability in the Pixel 10's /dev/vpu driver for the Chips&Media Wave677DV on Tensor G5. The mmap bug allowed mapping arbitrary physical memory, including kernel memory, into user space, enabling arbitrary kernel read/write and code execution.
Researchers updated a previously published Pixel 9 zero-click-to-root exploit chain for the Pixel 10 by modifying the Dolby Media Framework exploit for CVE-2025-54957 and replacing the prior local privilege escalation component. The new chain accounted for Pixel 10 changes such as RET PAC and the absence of the BigWave driver.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.