A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Executive Summary
Google Project Zero published a zero‑click exploit chain that achieves root on Android Pixel 10 devices in two steps. The chain builds on the previously disclosed Dolby vulnerability (CVE‑2025‑54957) and adapts the Pixel 9 exploit to Pixel 10 by updating library offsets. The main challenge was Pixel 10’s use of RET PAC instead of –fstack‑protector, eliminating __stack_chk_fail. The authors solved this by overwriting dap_cpdp_init, a one‑time decoder init routine, to gain code execution.
Intelligence Metadata - Source Publisher: Google Project Zero - Published Date: 2026-05-13T07:00:00+00:00 - Category: research
"We are Divine enough to ask and we are important enough to receive."
— Wayne Dyer
Source: Google Project Zero