← Retour au blog
tech 15 May 2026

A 0-Click Exploit Chain for Pixel 10: A New Window for Vulnerabilities

Explore how a new 0-click exploit chain threatens the Pixel 10, despite previous patches. This article delves into the technical challenges and implications for mobile security.

Article inspired by the original source
A 0-click exploit chain for the Pixel 10 ↗ projectzero.google

Introduction

The constant evolution of mobile technologies brings its share of security challenges. 0-click exploits, which require no user interaction, represent a growing threat. Recently, a 0-click exploit chain was discovered for the Pixel 10, highlighting persistent vulnerabilities even after recent patches.

Exploit Background

In May 2026, a 0-click exploit chain was published for the Pixel 10 by Google's Project Zero team. This type of exploit is particularly dangerous as it requires no user action to execute, making devices extremely vulnerable.

Updating the Dolby Exploit

The exploit initially developed for the Pixel 9 had to be adapted for the Pixel 10. One of the main modifications was adjusting the offsets in the targeted Dolby library. The Pixel 10 uses a protection mechanism called RET PAC, replacing -fstack-protector, complicating traditional exploitation. After several trials, the team managed to use the dap_cpdp_init initialization code to bypass this protection.

Removal of BigWave, Addition of VPU

Unlike the Pixel 9, the BigWave driver is not present on the Pixel 10. However, a new VPU driver, used for interacting with the Chips&Media Wave677DV silicon on the Tensor G5 chip, was identified. This driver presents a critical vulnerability that exposes the chip's hardware interface to userspace.

Implications and Consequences

This discovery underscores the importance of constant vigilance in security. Hardware vulnerabilities, like those found in the VPU driver, can have profound implications, potentially allowing attackers full control over affected devices.

The Mobile Security Challenge

Manufacturers must focus not only on regular software updates but also on thoroughly auditing new hardware components. The Pixel 10 case shows that even recent devices can be compromised if new technologies are not properly integrated and secured.

Conclusion

0-click exploits like the one discovered for the Pixel 10 demonstrate the need for a proactive approach to security. Tech decision-makers and developers must collaborate to anticipate and mitigate these threats.

Let's discuss your project in 15 minutes.

Pixel 10 0-click exploit mobile security Dolby exploit VPU vulnerability
Deepthix newsletter · 100% AI · every Monday 8am

An AI agent reads tech for you.

Our AI agent scans ~200 sources per week and ships the best articles to your inbox Monday 8am. Free. One click to unsubscribe.

Visit the newsletter page →

Want to automate your operations?

Let's talk about your project in 15 minutes.

Book a call