INTEL_REPORT
Google Project Zero · published 5/13/2026, 7:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10. Up…
https://projectzero.google/2026/05/pixel-10-exploit.html
sha256:69d730333170deeb2cbd691f929b8023cf699c90319f2fef3ea46be0a3a27e3d
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| cve | CVE-2025-54957 | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.