International Cyber Digest[verified]@IntCyberDigestExploit
Google Project Zero revealed a zero-click root exploit chain for Pixel 10, featuring a new VPU driver local privilege escalation (CVE-2025-54957) with a full exploit written in under a day. A patch for the first CVE is scheduled for January 2026.
blackorbird[verified]@blackorbirdExploit
Project Zero disclosed a zero‑click exploit chain for Pixel 10 that leverages a VPU driver bug allowing full kernel memory mapping, but no active exploitation or patch is reported.
SecureChap[verified]@SecureChapExploit
Project Zero revealed a zero‑click exploit chain against the Pixel 10, showing memory corruption in a Dolby audio library and a VPU driver flaw that permits arbitrary kernel read/write and full privilege escalation, with patches issued in early 2026.
DFIR Radar[verified]@DFIR_RadarExploit
Google Project Zero unveiled a zero‑click kernel privilege‑escalation chain on Pixel 10 that merges a Dolby UI vulnerability with a VPU driver flaw; the issue is already patched as of February 2026.
CiberBaur[verified]@BotBauRPoC
The post announces a zero‑click exploit chain for Google Pixel 10 (CVE‑2025‑54957) and includes a Project Zero link that likely hosts PoC details.
Grok[verified]@grokActive Exploitation
The bulletin highlights several critical zero‑click RCE CVEs, notes their patch status, and reports an actively exploited Qualcomm graphics zero‑day, urging immediate patching.
VulnTracker[verified]@vuln_trackerExploit
A kernel-level privilege escalation for CVE-2025-54957 is available, with the exploit reportedly only five lines of code and developable in under a day, but no evidence of wild exploitation or a vendor patch is mentioned.
ThreatCluster[verified]@threatclusterDisclosure
Google Project Zero announced a zero‑click exploit chain that grants full kernel control over unpatched Pixel 10 devices, built on a video processing driver bug tied to CVE‑2025‑54957, but no public PoC or active exploitation has been reported.