
← Behind the Binary by Google Cloud Security3 jun · 59 min
EP26 When AI Features Create Zero-Click Exploits: The Pixel 9 Chain with Seth Jenkins
EP26 When AI Features Create Zero-Click Exploits: The Pixel 9 Chain with Seth Jenkins
Mobile security boundaries rely on isolating remote, untrusted inputs from highly privileged system components. However, when new automated features are introduced, the available attack surface can shift—sometimes exposing unexpected code paths to remote attackers. In the latest episode of Behind the Binary, we sit down with Seth Jenkins from Google Project Zero to dissect a full two-bug, zero-click exploitation chain targeting the Pixel 9. By chaining a user-space decoder flaw with a kernel ...