|
|
Log in / Subscribe / Register

Sandboxing?

Sandboxing?

Posted Jan 17, 2026 15:32 UTC (Sat) by paulj (subscriber, #341)
In reply to: Sandboxing? by josh
Parent article: A 0-click exploit chain for the Pixel 9 (Project Zero)

The decoder _is_ running in a sandbox. They used the decoder bug to then deliver /another/ exploit for the kernel driver for the "BigWave" hardware AV1 decoder - which is accessible from the 'mediacodec' sandbox used for decoding media (though, doesn't seem like this driver was necessary for /particular/ decoder involved in the initial attack). They quickly found 3 different exploitable bugs in said driver, so.. spoiled for choice there.

So, exploit the sandboxed media decoder to deliver the exploit for the hardware decoder acceleration driver -> code execution in kernel -> game over.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds