Live data from Hacker News

A 0-Click Exploit Chain for the Pixel 10

blackhat.com

1–3 of 3 posts

Re: A 0-Click Exploit Chain for the Pixel 10

#3

Apparently this exploit requires playing a crafted media clip. I wonder if the exploit would be effective against Pixel 10s running GrapheneOS...

Playing the clip yourself would only be the one-click route. The exploit's actual significance is the zero-click path, where Google Messages auto-transcribes incoming audio and triggers the Dolby decode without any interaction at all.

A device running a 6+-month-old GrapheneOS version and having Google Messages installed would be vulnerable to that zero-click. The key question is whether and how it could be utilised to get past BFU mode. Maybe they can find another entry point via cellular/WiFi, as very few GOS users will have Google Messages installed anyway. So this might be the first zero-click on GOS, but it's still very speculative, as there is no public PoC. And it matters only for devices that didn't get updates.