PortsuppeApp
SucheQuellenÜberDE/EN

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

Google Project Zero·vor 133 d·Offiziell

With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV

Kategorien cybersecurity
Originalquelle / Advisory
Veröffentlicht
14.1.2026, 09:00:00
Abgerufen
27.5.2026, 04:13:24
Trust
official · 100/100
Sprache
en