Introduction
The constant evolution of mobile technologies brings its share of security challenges. 0-click exploits, which require no user interaction, represent a growing threat. Recently, a 0-click exploit chain was discovered for the Pixel 10, highlighting persistent vulnerabilities even after recent patches.
Exploit Background
In May 2026, a 0-click exploit chain was published for the Pixel 10 by Google's Project Zero team. This type of exploit is particularly dangerous as it requires no user action to execute, making devices extremely vulnerable.
Updating the Dolby Exploit
The exploit initially developed for the Pixel 9 had to be adapted for the Pixel 10. One of the main modifications was adjusting the offsets in the targeted Dolby library. The Pixel 10 uses a protection mechanism called RET PAC, replacing -fstack-protector, complicating traditional exploitation. After several trials, the team managed to use the dap_cpdp_init initialization code to bypass this protection.
Removal of BigWave, Addition of VPU
Unlike the Pixel 9, the BigWave driver is not present on the Pixel 10. However, a new VPU driver, used for interacting with the Chips&Media Wave677DV silicon on the Tensor G5 chip, was identified. This driver presents a critical vulnerability that exposes the chip's hardware interface to userspace.
Implications and Consequences
This discovery underscores the importance of constant vigilance in security. Hardware vulnerabilities, like those found in the VPU driver, can have profound implications, potentially allowing attackers full control over affected devices.
The Mobile Security Challenge
Manufacturers must focus not only on regular software updates but also on thoroughly auditing new hardware components. The Pixel 10 case shows that even recent devices can be compromised if new technologies are not properly integrated and secured.
Conclusion
0-click exploits like the one discovered for the Pixel 10 demonstrate the need for a proactive approach to security. Tech decision-makers and developers must collaborate to anticipate and mitigate these threats.
Let's discuss your project in 15 minutes.