Live data from Hacker News

A 0-click exploit chain for the Pixel 10

projectzero.google

101–110 of 255 posts

Re: A 0-click exploit chain for the Pixel 10

#101

Earlier quoted context omitted.

If this rule were implemented, would you be walking free right now? Think it over.

Pretty sure the million dollars was not meant seriously. There are plenty of regulated fields in which people still participate, despite various risks of liability. Professional engineers, doctors, every Uber driver in the US, who could potentially be punished for negligent driving while on the job. The point, I think, is that the current level of responsibility for writing bad code is essentially zero, but should pr…

> the current level of responsibility for writing bad code is essentially zero, but should probably be higher for some applications

I agree that e.g. working on an OS should require guild-type credentials. But I don't know if most SWEs understand the professional-standards requirements such organisations are empowered to enforce on their members.

Re: A 0-click exploit chain for the Pixel 10

#102
post #4

"This is notably fast given that this is the first time that an Android driver bug I reported was patched within 90 days of the vendor first learning about the vulnerability." This makes me feel better about Google, but also makes me kind of frightened of the rest of Android. I wonder what Apple's response time is?

Android vendors have been notorious about updates for a long time. Part of that is supposedly because all of the phone companies want to distinguish themselves from each other, and so they all want to fork the default Android UI so they can offer some psychedelic UI vision with some brand-specific features. But that means that when an update to stock Android comes out, it's a lot of work to migrate.

I don't think Android UI customization is the main issue. Many vendors are not even able to keep device firmware and Linux kernels in sync. Qualcomm and others are doing monthly bulletins:

https://docs.qualcomm.com/securitybulletin/may-2026-bulletin...

Since a lot of vendors are months or even years behind, their phones are full of known holes.

When it comes to security, basically: GrapheneOS > iOS > PixelOS >> Samsung OneUI >>>>>>>> everybody else.

Sadly, Samsung lets anyone who pays enough push bloatware and analytics on their phones. E.g. AppCloud from an Isreali company, Meta services that stay even when you remove Meta apps (only removable with ADB/UAD), etc. So there are only three somewhat serious options (and for two of them, you still give a lot of analytics to Apple or Google).

Re: A 0-click exploit chain for the Pixel 10

#103
post #64

Earlier quoted context omitted.

That's not really a fair test because you're leading the model pretty hard, even if the prompt doesn't specifically say there's a bug to be found. It's basically the same objections that people raised in the thread where someone claimed current models are just as good as mythos.

right exactly, but clearly it's possible to elicit the behavior we want in the model, which means the capabilities are there!

The more interesting question is, how many issues will this prompt report to you in random code that is perfectly fine?

Re: A 0-click exploit chain for the Pixel 10

#104
post #98
post #97

Earlier quoted context omitted.

... really? Zero-click RCEs can be used on arbitrarily many phones until they are discovered which usually takes on the order of months. You do not need to burn them on every individual target. As a example of how they might be used in that fashion for profit, NSO group had a revenue of 240 million dollars in 2020. Many of their customers were governments who wanted to spy on activists and journalists. NSO group was…

You’re right, I misstated. It’s not 10 million per exploitation , it instead limits the pool of people who can exploit you to those willing and have the ability to spend 10 million+ on an exploit. That is still quite a small pool, and there are other network effects preventing any Joe blogs with that much capital from launching an exploitation campaign.

Again, no. You do not need to spend 10 million on a exploit if you are working with a company like NSO Group who sells white-glove access to target individual as a service. The cost lower bound is going to be on the order of ((cost of exploit) / (number of times exploit can be used)) and the denominator there is going to easily be in the hundreds to thousands. Of course prices are likely to be higher than the minimum due to profit margins.

To, once again, use the same example of NSO Group as it is infamous and well-documented [1]. In 2016 it was 500,000 $ upfront and 650,000 $/year for 10 devices. That article claims Saudi Arabia was monitoring 15,000 phones at a average cost of 10,000 $/phone. In [2] it was 7 million $ for 15 devices, but the upfront versus marginal cost per device is not broken down. And this was a relatively "above-board" company in the sense that they were a legitimate business entity with government deals which commands a premium relative to random unknown blackhat organization with no reputation.

And again, my original comment was discussing commercial profit-motivated attackers for which 1 million $ is easily within reach and just a cost of doing business to unlock greater amounts of profit. That is less than the cost of setting up a McDonalds. There is a vast, vast gap spanning factors of millions between Joe Schmo and commercial actors and a even vaster gap to state actors. There is no evidence that Lockdown mode is adequate against even commercial actors, let alone the vastly more capable state actors.

[1] https://prodefence.io/news/pegasus-spyware-operating-costs-c...

[2] https://www.reuters.com/business/media-telecom/meta-suit-aga...

Re: A 0-click exploit chain for the Pixel 10

#105
post #54

Earlier quoted context omitted.

Or it becomes standardized to have exclusions - pilots for example often have extensive insurance that covers the company when they’re flying for hire, but covers nothing if puttering around in a Cessna on the weekend. Insurance companies are very, very good at figuring out how to identify and price risk, once motivated to do so.

Sure as you'd expect lawyers are better at cutting a good deal for themselves than other professions, but I wanted to cite an example where it does work out. Also from what I've seen there are way too many GA accidents involving airline pilots for the insurers to eat that loss. They almost invariably have superior skills, but some of them more than compensate with risk taking.

It's not about lawyers cutting a good deal for themselves. Liability issues get complicated along multiple dimensions when they involve licensed professionals, even when they're day-to-day working relationship is indistinguishable from any other employee. And lawyers, even more than doctors, are at the furthest extreme of this complication spectrum. Even were software engineering to become a mandatorily licensed profession like some other engineering disciplines, there's little reason to believe insurance products would mirror those in the legal profession. I seriously doubt we'd end up in a place where employers are common--let alone routinely--paying to cover liability for work outside the scope of employment.

Re: A 0-click exploit chain for the Pixel 10

#106
post #96
post #94

Earlier quoted context omitted.

LARPing is imagining that Lockdown mode protects you from state-level actors. It is frankly baffling why a industry that has been laughing for literal decades at even the possibility of stopping state-level actors just turns around and uncritically believes Apple's marketing team with literally zero support, evidence or proof except for a long track record of failure. You would think that extraordinary claims would d…

> We have seen multiple software hacks resulting in >10 million dollar payouts This sets a nice price bar for exploitation. Is someone willing to pay 10+ million dollars to get access to your phone? The obvious caveat here is that for a lot less than 10 million dollars someone can be hired to hit you with a metal pipe until you give up your passcode. > click total compromise that can trivially worm to take down hundr…

Is someone willing to pay 10+ million dollars to get access to your phone?

Not yours specifically usually, but there is a lot of money in a general tool that law enforcement can use to read out phones. Of course, most of them focus on physical access. In the few Cellebrite reports/presentations that have leaked, iPhones would fall after a relatively short time (IIRC a few months), but did better than most Android phones (except GrapheneOS).

Also, sometimes you do not need the 10M exploit, you can buy many cheaper exploits and make a chain yourself.

The obvious caveat here is that for a lot less than 10 million dollars someone can be hired to hit you with a metal pipe until you give up your passcode

If they hit you with a metal pipe, it's likely that you won't survive even if you give up your passcode. So most likely you are protecting something or someone else. Set up a duress PIN so that you have options in that case.

Re: A 0-click exploit chain for the Pixel 10

#107
post #54

Earlier quoted context omitted.

Or it becomes standardized to have exclusions - pilots for example often have extensive insurance that covers the company when they’re flying for hire, but covers nothing if puttering around in a Cessna on the weekend. Insurance companies are very, very good at figuring out how to identify and price risk, once motivated to do so.

Sure as you'd expect lawyers are better at cutting a good deal for themselves than other professions, but I wanted to cite an example where it does work out. Also from what I've seen there are way too many GA accidents involving airline pilots for the insurers to eat that loss. They almost invariably have superior skills, but some of them more than compensate with risk taking.

It's because it's simpler to insure "everything real estate" or whatever than to try to cut out exclusions for (relatively) cheap properties.

But if they noticed that they were paying out more than expected on these $500k deals, the insurance would change quite quickly.

The same thing happened with GA insurance - there was an assumption that airline pilots would be safer but it didn't really turn out as expected, because a 747 has a heck of a lot more "keep you safe" doohickeys and doesn't fly low to the ground much.

Re: A 0-click exploit chain for the Pixel 10

#108
post #94
post #62

Earlier quoted context omitted.

This makes sense if you’re a human-rights journalist working in a dangerous country, with the threat of state-level actors looking to compromise you. If you’re not then this seems quite paranoid, bordering on LARPing.

LARPing is imagining that Lockdown mode protects you from state-level actors. It is frankly baffling why a industry that has been laughing for literal decades at even the possibility of stopping state-level actors just turns around and uncritically believes Apple's marketing team with literally zero support, evidence or proof except for a long track record of failure. You would think that extraordinary claims would d…

I strongly disagree that there is no evidence that Lockdown mode is effective; there have been numerous exposed, active iOS exploitation campaigns of which none have worked against Lockdown mode. When we're trying to prove a negative, that's actually some of the strongest evidence we can get.

The economics of the device exploitation industry are completely orthogonal from bug bounty payouts; the markets only overlap at the _extreme_ fringes. Trying to use one as a proxy for the other is meaningless.

Re: A 0-click exploit chain for the Pixel 10

#109
post #66

I followed the link to the Pixel 9 bug/exploit and saw this: "Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user" Haven't we learned our lesson on this…

> Don't read and act on my sms messages without me asking you to!

Somewhere there's an NSA agent reading this and laughing like a gin addict on payday.

Re: A 0-click exploit chain for the Pixel 10

#110
post #61
post #59

Earlier quoted context omitted.

Published CVEs seems a bad metric to use for this- unless we assume that the ratio of really nasty vulns/not-too-bad vulns is consistent.

Also the question remains if more CVE laden code was produced in the first place, instead of automated detection improvements. It's easier to find a needle in the haystack if the haystack is 50% needles.

have the AI vibe code crappy apps so the related AI vuln finder can fix them

just doubled the value and use cases of your AI solution!

Post reply on HN