CVE Tools

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

Google Project ZeroBy Seth Jenkins5 min read

PoC publicGoogle PixelAndroid
Read at Google Project Zero

Below is the opening; the full story is at Google Project Zero.

From Google Project Zero

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10.…

Continue at Google Project Zero

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store