Live data from Hacker News

A 0-click exploit chain for the Pixel 10

projectzero.google

51–60 of 255 posts

Re: A 0-click exploit chain for the Pixel 10

#51

Semi-related: has the rate of published exploits picked up as if late, or is it simply the fact that there’s hype around ai as security tool (offense or defense) so it’s simply in the news more often? Feels like there’s something new every other day - linux, windows, mobile, various commonplace tools used by everybody, the list goes on

I just did some analysis on this last weekend, in 2024 there were roughly 100 CVEs published every day. In April we hit approximately 200 per day.

Going backwards from 2023, the doubling interval for published CVEs was approximately 4 to 4 1/2 years. Since then it’s approximately two years.

There has definitely been a rapid uptick.

Re: A 0-click exploit chain for the Pixel 10

#52

Semi-related: has the rate of published exploits picked up as if late, or is it simply the fact that there’s hype around ai as security tool (offense or defense) so it’s simply in the news more often? Feels like there’s something new every other day - linux, windows, mobile, various commonplace tools used by everybody, the list goes on

If one reads between the lines in part 1, the code in question was introduced due to AI features and the exploit was found by humans:

https://projectzero.google/2026/01/pixel-0-click-part-1.html

So AI usage increases bugs and humans have to weed them out!

Re: A 0-click exploit chain for the Pixel 10

#53
And that is against a device whose BSP is actually open source and available for research!

Now imagine the dark horrors hiding in the BSPs of other Android devices... or embedded devices in general.

Frankly, it should be a requirement of Google's certification process that everything regarding drivers gets upstreamed into the Linux kernel. Yes, even if this adds quite a time delay to the usual hardware development process.

Re: A 0-click exploit chain for the Pixel 10

#54

Earlier quoted context omitted.

I would stop writing code for money.

Well, one scenario would be that everybody who writes code would do so for money. Take my friend who is a property lawyer. The firm she works for buys her insurance, because it would be insane to operate without insurance, but the only available insurance is personal insurance, it insures a specific person to do property law. So, although her day job is helping that $100Bn farm equipment company buy a $10M new factor…

Or it becomes standardized to have exclusions - pilots for example often have extensive insurance that covers the company when they’re flying for hire, but covers nothing if puttering around in a Cessna on the weekend.

Insurance companies are very, very good at figuring out how to identify and price risk, once motivated to do so.

Re: A 0-click exploit chain for the Pixel 10

#55

fascinating how GrapheneOS achieves high security level on the same hardware where Google failed to even randomize android's kernel location

It's easy to be secure if you just remove features. There's obvious tension here.

Could you be any more specific about what features they've removed such that the hardening functions work? Because I think there are none

Re: A 0-click exploit chain for the Pixel 10

#57
post #8

fascinating how GrapheneOS achieves high security level on the same hardware where Google failed to even randomize android's kernel location

google has lost its focus with pixel phones

on selling ads or what do you mean their focus used to be that they've lost? I'm not at all negative about more paid features that they've been offering over time, from workspace to youtube to hardware. Still very conflicted about giving Google of all places my custom, but for e.g. phones it's hard to avoid and second-hand the prices are really quite competitive for a tangible hardware product (not a software subscription that you're stuck on). Not bad to shift focus to making these Pixel devices imo, so long as they remain open that is

Re: A 0-click exploit chain for the Pixel 10

#58
post #4

"This is notably fast given that this is the first time that an Android driver bug I reported was patched within 90 days of the vendor first learning about the vulnerability." This makes me feel better about Google, but also makes me kind of frightened of the rest of Android. I wonder what Apple's response time is?

I've reported security bugs to Apple before. Was a couple years back but I remember it taking around 6 months to patch (there was a couple back and forth for me to get a more reliable POC). Maybe 2 months from when I submitted a POC with 100% reproducibility

Not sure how much it helps, but I just run all my Apple devices in "Lockdown mode", don't install apps (use Safari), and try to mostly use Safari in private sandboxed mode.

Re: A 0-click exploit chain for the Pixel 10

#59
post #51

Semi-related: has the rate of published exploits picked up as if late, or is it simply the fact that there’s hype around ai as security tool (offense or defense) so it’s simply in the news more often? Feels like there’s something new every other day - linux, windows, mobile, various commonplace tools used by everybody, the list goes on

I just did some analysis on this last weekend, in 2024 there were roughly 100 CVEs published every day. In April we hit approximately 200 per day. Going backwards from 2023, the doubling interval for published CVEs was approximately 4 to 4 1/2 years. Since then it’s approximately two years. There has definitely been a rapid uptick.

Published CVEs seems a bad metric to use for this- unless we assume that the ratio of really nasty vulns/not-too-bad vulns is consistent.

Re: A 0-click exploit chain for the Pixel 10

#60

Earlier quoted context omitted.

I've reported security bugs to Apple before. Was a couple years back but I remember it taking around 6 months to patch (there was a couple back and forth for me to get a more reliable POC). Maybe 2 months from when I submitted a POC with 100% reproducibility

Not sure how much it helps, but I just run all my Apple devices in "Lockdown mode", don't install apps (use Safari), and try to mostly use Safari in private sandboxed mode.

Are you at an above average risk of being targeted by a state level threat actor?
Post reply on HN