Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

Summary

Second part of Project Zero's Pixel 9 zero-click chain research: auditing the BigWave AV1 decoder driver reachable from the mediacodec sandbox and finding bugs that yield kernel read and write.
Published
Collected

original ↗