Google Project Zero disclosed several memory corruption vulnerabilities in Samsung's Shannon baseband stack tied to parsing Session Description Protocol (SDP) fields, including fmtp, acfg, pcfg, accept-type, and chatroom attributes. The issues indicate malformed SDP data could trigger unsafe memory handling inside the baseband processor, expanding the attack surface in cellular communications components that operate below the main operating system.
The grouped reports show a pattern of parser weaknesses in the Shannon baseband's handling of multiple SDP attribute types rather than a single isolated bug. While the issue listings provide limited technical detail, the repeated findings suggest systemic input-validation and memory-safety problems in a highly privileged mobile subsystem, raising the risk of crashes, code execution, or broader compromise depending on exploitability and device exposure.

See affected versions and whether adversaries are exploiting it.
24 events from the most recent confirmed update back to the earliest known activity.
Project Zero published an issue titled "Windows: Administrator Protection RAiLaunchAdminProcess Application Name EoP." The reference indicates disclosure of a further Windows elevation-of-privilege vulnerability.
Project Zero published an issue titled "Windows: Administrator Protection MSIX Sideloading UI Access EoP." This marks disclosure of another Windows elevation-of-privilege issue in the same feature area.
Project Zero published an issue titled "Windows: Administrator Protection LowBox UI Access Token EoP." The reference indicates disclosure of a Windows privilege-escalation flaw.
Project Zero published an issue titled "Administrator Protection RAiLaunchAdminProcess Debugging Flag EoP." This marks disclosure of a Windows elevation-of-privilege issue related to Administrator Protection.
Project Zero published an issue stating that arm64 linear mapping was mapped at the same static virtual address. This indicates disclosure of a platform security weakness affecting address layout assumptions.
Project Zero published an issue titled "MacOS Sandbox Escape via Double Free in coreaudiod/CoreAudio Framework." The reference indicates disclosure of another macOS sandbox escape flaw.
Project Zero published an issue stating that Linux 6.9 and later had broken AF_UNIX MSG_OOB handling causing a use-after-free read and write condition.
Project Zero published an issue describing incorrect bailout unwinding in cvp that led to a use-after-free dangling list entry.
Project Zero published an issue titled "MacOS Sandbox Escape via Type Confusion in coreaudiod/CoreAudio Framework." This marks disclosure of a macOS sandbox escape vulnerability.
Project Zero published an issue describing a race between npu_host_unload_network and npu_host_exec_network_v2 that led to memory corruption in msm_npu.
Project Zero published an issue stating that insufficient locking in edgetpu_pin_user_pages caused race conditions leading to kernel memory corruption.
Project Zero published an issue describing memory corruption in the Shannon baseband when processing the accept-type SDP attribute.
Project Zero published an issue describing memory corruption in the Shannon baseband when processing the fmtp SDP attribute.
Project Zero published an issue describing memory corruption in the Shannon baseband when processing acfg and pcfg SDP attributes.
Project Zero published an issue describing memory corruption in the Shannon baseband when processing the chatroom SDP attribute.
Project Zero published an issue describing Apple Safari remote code execution via an undefined othersubr in Type 1 fonts handled by libType1Scaler.dylib on macOS and iOS.
Project Zero published an issue titled "JSC: JSValue use-after-free in ValueProfiles." The reference indicates disclosure of a use-after-free vulnerability in JavaScriptCore.
Project Zero published an issue describing a JavaScriptCore DFG loop-invariant code motion bug that left object property access unguarded. This represents disclosure of a browser engine security flaw.
Project Zero published an issue titled "VMSF_DELTA filter in unrar allows arbitrary memory write." The available extract indicates a vulnerability record for an arbitrary memory write flaw in unrar.
Project Zero published an issue titled "CPUs: information leak using speculative execution." This marks disclosure of a CPU-side information leak vulnerability class later associated with speculative execution attacks.
Project Zero published an issue titled "cloudflare: Cloudflare Reverse Proxies are Dumping Uninitialized Memory." The reference indicates disclosure of an information exposure flaw affecting Cloudflare reverse proxies.
Project Zero published an issue describing a path from an unprivileged host user to host kernel privilege escalation in VirtualBox via environment variables and ioctl handling.
Project Zero published an issue titled "Windows: DCOM DCE/RPC Local NTLM Reflection Elevation of Privilege." This marks disclosure of another Windows elevation-of-privilege vulnerability.
Project Zero published an issue titled "Windows: DosDevices Impersonation Elevation of Privilege." The reference indicates disclosure of a Windows local privilege-escalation vulnerability.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
22 references tracked. Mallory keeps watching after this page renders.
project-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.