David Bombal

← David Bombal4 days ago · 39 min

#601: Google Researchers Hacked the Pixel Phone using Audio Messages

#601: Google Researchers Hacked the Pixel Phone using Audio Messages4 days ago39 min

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.

David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.

The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.

They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.

Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.

These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.

// Seth Jenkins SOCIAL //

LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/

X: https://x.com/__sethJenkins

// Natalie Silvanovich SOCIAL //

X: https://x.com/natashenka?lang=en