CVE-2025-54957Exploit

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is processed. When Evolution data is processed by evo_priv.c from the DD+ bitstream, the decoder writes that data into a buffer. The length calculation for a write can overflow due to an integer wraparound. This can lead to the allocated buffer being too small, and the out-of-bounds check of the subsequent write to be ineffective, leading to an out-of-bounds write.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Peaked 5d ago at 2 mentions (2026-05-13); latest day: 2
  • 10 total mentions across 7 days

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-03-10: 1Mentions · 2026-05-13: 2Mentions · 2026-05-14: 1Mentions · 2026-05-15: 2Mentions · 2026-05-16: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-20: 1Exploit Tool / Code · 2026-05-14: 1Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-19: 1Exploit Tool / Code · 2026-05-20: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 2Technical Details · 2026-03-10: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 103-1005-1305-1405-1505-1605-1905-20
Signal classification6 categories
Exploit
550.0%
Active Exploitation
110.0%
PoC
110.0%
Patch
110.0%
Disclosure
110.0%
General
110.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-101
Active Exploitation1
2026-05-132
Exploit1PoC1
2026-05-141
Exploit1
2026-05-152
Exploit1Patch1
2026-05-161
Disclosure1
2026-05-191
Exploit1
2026-05-202
Exploit1General1
Full discourse10 posts
  • International Cyber Digest@IntCyberDigest
    Exploit

    🚨 Google Project Zero just published a Pixel 10 zero-click to root exploit chain. Two vulnerabilities and less than a day of work to weaponize the second one. Chain: - Stage 1: same Dolby UDC zero-click (CVE-2025-54957) used against the Pixel 9. Patched in January 2026. Only minor offset updates and a tweak around RET PAC needed to port to Pixel 10 - Stage 2: a brand new local privilege escalation in the VPU driver for the Chips&Media Wave677DV on the Tensor G5 Result: arbitrary kernel read/write in 5 lines of code. Full exploit written in under a day.

    Post summary

    Google Project Zero revealed a zero-click root exploit chain for Pixel 10, featuring a new VPU driver local privilege escalation (CVE-2025-54957) with a full exploit written in under a day. A patch for the first CVE is scheduled for January 2026.

    9811280927968.0K
    193.6K followersView on X
  • blackorbird@blackorbird
    Exploit

    Google Project Zero published a 0-click exploit chain for the Pixel 10 that can achieve root access on Android using just two vulnerabilities. Dolby zero-click exploit (CVE-2025-54957) to work on Pixel 10 with minor changes. The old BigWave driver (used for privilege escalation on Pixel 9) is gone, but they found a new, extremely simple bug in the VPU driver (/dev/vpu) for the Tensor G5 chip's video decoder. The VPU bug allows any app to map the entire kernel memory into user space via a flawed mmap function — essentially giving full read/write access to kernel code and data. https://projectzero.google/2026/05/pixel-10-exploit.html ref: vpu driver mmap allows OOB physical mappings [463438263] https://project-zero.issues.chromium.org/issues/463438263

    Post summary

    Project Zero disclosed a zero‑click exploit chain for Pixel 10 that leverages a VPU driver bug allowing full kernel memory mapping, but no active exploitation or patch is reported.

    12911789022.7K
    42.9K followersView on X
  • final@__final__
    Patch

    CVE-2025-54957 was patched upstream in December through a Pixel update prior. The article also references that this is a porting of a Pixel 9 exploit chain of theirs mentioning a weakness in a weak exploit mitigation (KASLR) that's long resolved in GrapheneOS. Great work by P0.

    Post summary

    CVE-2025-54957 was already patched in December via a Pixel update; the post references a prior Pixel 9 exploit chain but gives no evidence of new PoC or active exploitation.

    100401.8K
    116 followersView on X
  • SecureChap@SecureChap
    Exploit

    Project Zero published a full 0-click exploit chain against the Pixel 10. Stage 1: CVE-2025-54957 in the Dolby UDC audio decoder library running in mediaserver. Processing untrusted media triggers memory corruption through syncframe offset manipulation. The updated technique overwrites the dap_cpdp_init function pointer to bypass PAC-RET. Patched in the January 2026 Android security bulletin. Stage 2: Bug in the VPU driver at /dev/vpu on Tensor G5's Chips&Media Wave677DV. The vpu_mmap() handler calls remap_pfn_range() without checking the size against the register region. An mmap syscall with a size larger than the region maps arbitrary physical memory. On Pixel, the kernel sits at a fixed physical address. Attackers use the known offset between the VPU MMIO region and the kernel - no scanning required. Arbitrary kernel read/write in five lines of code. From there, kernel code execution and root. Seth Jenkins and Jann Horn audited the VPU driver and spotted the flaw in under two hours. They built the full LPE exploit in less than one day. Reported November 24, 2025. Patched February 2026 - 71 days later. Affected Pixel 10 devices with SPL of December 2025 or earlier. Hardware vendors skipping framework safeguards turn media decoders into kernel gateways.

    Post summary

    Project Zero revealed a zero‑click exploit chain against the Pixel 10, showing memory corruption in a Dolby audio library and a VPU driver flaw that permits arbitrary kernel read/write and full privilege escalation, with patches issued in early 2026.

    010111.9K
    156 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2020-17103 2 - CVE-2026-8507 3 - CVE-2026-3854 4 - CVE-2026-46333 5 - CVE-2025-54957 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post only lists several CVE identifiers with no additional technical, exploit, or mitigation details.

    001101.2K
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Google 🇺🇸 Project Zero demonstrates new 0-click to root exploit chain on Pixel 10, combining updated Dolby vulnerability with critical VPU driver flaw that exposes entire kernel memory to userspace modification. Key technical details: • CVE-2025-54957: Updated Dolby UDC exploit bypasses RET PAC protections by targeting dap_cpdp_init initialization code instead of __stack_chk_fail • VPU driver flaw: vpu_mmap() function lacks bounds checking, allowing unlimited physical memory mapping via remap_pfn_range() • Kernel exploitation: Fixed physical address layout enables direct kernel .text/.data overwrite without memory scanning • Attack surface: /dev/vpu accessible from mediacodec SELinux context on Tensor G5 devices Exploitation chain: • Stage 1: 0-click Dolby vulnerability gains initial code execution • Stage 2: VPU driver maps kernel memory into userspace with 5 lines of code • Full privilege escalation achieved in under 24 hours development time DFIR artifacts: • Look for unusual mmap() syscalls with large size parameters targeting /dev/vpu • Monitor mediacodec process memory mappings for suspicious physical address ranges • Check for unexpected kernel memory modifications in crash dumps Hunt for processes accessing /dev/vpu with oversized memory mappings. Patched in February 2026 SPL - verify device patch levels. #DFIR_Radar

    Post summary

    Google Project Zero unveiled a zero‑click kernel privilege‑escalation chain on Pixel 10 that merges a Dolby UI vulnerability with a VPU driver flaw; the issue is already patched as of February 2026.

    10010986
    1.5K followersView on X
  • CiberBaur@BotBauR
    PoC

    ⚠️ ALERTA: Descubierta cadena de exploits de 0 clics para Google Pixel 10. Acceso a raíz del sistema Android en 2 exploits. CVE-2025-54957. https://projectzero.google/2026/05/pixel-10-exploit.html #CiberseguridadMX #CyberSecurity #Ransomware

    Post summary

    The post announces a zero‑click exploit chain for Google Pixel 10 (CVE‑2025‑54957) and includes a Project Zero link that likely hosts PoC details.

    00011968
    315 followersView on X
  • Grok@grok
    Active Exploitation

    Latest as of Mar 2026: - CVE-2025-48593 (Nov 2025 bulletin): Critical zero-click RCE in Android System/Bluetooth component (A13-16). No user interaction or privileges needed; patched at security level 2025-11-01. - Project Zero Pixel 9 0-click chain (disclosed Oct 2025): Dolby UDC audio decoder (CVE-2025-54957) + kernel driver; patched on Pixel Jan 2026. - Mar 2026 bulletin: CVE-2026-0006 critical RCE in Media Codecs (no user interaction needed). Actively exploited zero-day CVE-2026-21385 is Qualcomm graphics (local, not zero-click). Update ASAP to latest patch level.

    Post summary

    The bulletin highlights several critical zero‑click RCE CVEs, notes their patch status, and reports an actively exploited Qualcomm graphics zero‑day, urging immediate patching.

    01000124
    8.4M followersView on X
  • VulnTracker@vuln_tracker
    Exploit

    @blackorbird CVE-2025-54957 (Dolby 0-click) + BigWave driver LPE = full kernel compromise. The kicker? The kernel exploit took 5 lines of code and less than a day to write. This is what "Holy Grail" looks like. http://vulntracker.io

    Post summary

    A kernel-level privilege escalation for CVE-2025-54957 is available, with the exploit reportedly only five lines of code and developable in under a day, but no evidence of wild exploitation or a vendor patch is mentioned.

    000001.2K
    653 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Google Project Zero reveals zero-click exploit chain giving full kernel control on unpatched Pixel 10 via video processing driver bug building on CVE-2025-54957. https://threatcluster.io/cluster/zero-click-exploit-chain-discovered-for-google-pixel-10-e3b03a90

    Post summary

    Google Project Zero announced a zero‑click exploit chain that grants full kernel control over unpatched Pixel 10 devices, built on a video processing driver bug tied to CVE‑2025‑54957, but no public PoC or active exploitation has been reported.

    000001.7K
    276 followersView on X

Explore more