news.volyx.in

A 0-click exploit chain for the Pixel 10 (projectzero.google)

448 points by happyhardcore · 106 days ago · 241 comments on HN

Article summary

A 0-click exploit chain for the Google Pixel 10 has been discovered, allowing for arbitrary read-write access to the kernel. The exploit chain consists of two parts: an updated Dolby exploit and a new vulnerability in the VPU driver. The vulnerability in the VPU driver was patched 71 days after its initial report. The discovery of this exploit chain highlights the ongoing need for more robust and security-aware code in Android drivers.

Main themes

  • Android security
  • 0-click exploits
  • Lockdown mode
  • AI in security research
  • State-level threats
  • Vulnerability discovery
  • Exploit economics
  • Device security

What commenters say

  • Some argue that expertise is still immensely valuable, especially in niche areas, and that AI is not yet capable of replacing human security researchers.
  • Others believe that AI can be used to find vulnerabilities, but it may not be effective in finding all types of bugs and may produce false positives.
  • There is a debate about the effectiveness of Lockdown mode in protecting against state-level actors, with some arguing that it is not a foolproof solution and that state actors can still find ways to compromise devices.
  • The cost and difficulty of finding zero-click RCEs is a topic of discussion, with some arguing that it would require hundreds of millions of dollars and a team of skilled individuals to find such exploits.
  • Some commenters believe that the threat of state-level actors is overblown and that Lockdown mode is not necessary for most users.
  • Others argue that the threat is real and that Lockdown mode is a necessary precaution, even if it may not be perfect.
  • The economics of the device exploitation industry is seen as a factor in the development and use of exploits, with some arguing that the cost of finding exploits is not directly related to bug bounty payouts.
  • The effectiveness of Lockdown mode is also questioned in terms of its ability to protect against novel and durable exploits developed by state actors.