1. A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

    Google Project ZeroResearchers report developing a zero-click exploit chain for Google’s Pixel 10, following earlier work on a similar chain for Pixel 9. The description connects the prior Android-wide Dolby vulnerability to a patch released in January 2026, but provides no details about the Pixel 10 chain’s impact or status.

  2. Image: Google Project Zero

    Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

    Google Project ZeroA security researcher details exploitation of CVE-2024-54529, a type confusion vulnerability in macOS’s coreaudiod daemon, alongside the related double-free vulnerability CVE-2025-31235. The work uses knowledge-driven fuzzing to find the flaws and examines how the first vulnerability can be exploited.

  3. A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?

    Google Project ZeroResearchers discuss broader Android ecosystem issues they encountered while finding, reporting and exploiting zero-click vulnerabilities in a Pixel 9 exploit chain. They focus on the Dolby audio attack surface and offer recommendations for improvement.

  4. Bypassing Windows Administrator Protection

    Google Project ZeroA security analysis examines how to bypass Administrator Protection, a feature introduced in Windows 11, 25H2 to replace User Account Control and limit local users' administrator access to when it is needed. It reviews how the feature works and how it differs from UAC.

  5. Image: Google Project Zero

    How to fix a bug in a fix

    Google Project ZeroGoogle Project Zero discusses challenges software vendors face when a vulnerability causes immediate user harm but patch-delivery systems limit how quickly they can fix it. The team considers how to address bugs in existing fixes and improve security remediation.

  6. Image: Google Project Zero

    On the Effectiveness of Mutational Grammar Fuzzing

    Google Project ZeroThe research examines mutational grammar fuzzing, in which a fuzzer changes samples while preserving structures defined by a grammar. It also discusses coverage-guided grammar fuzzing, where coverage informs which mutations are pursued.

  7. A Deep Dive into the GetProcessHandleFromHwnd API

    Google Project ZeroA security researcher examines the Windows GetProcessHandleFromHwnd API after encountering it in a publicly disclosed UAC bypass involving the Quick Assist UI Access application. The post starts with a review of the API's documentation and investigates how it works.