A 0-Click Exploit Chain For The Pixel 10

Natalie Silvanovich, Seth Jenkins

OffensiveCon 2026 · Day 1 · Main Stage

This talk, presented by Google Project Zero researchers Natalie Silvanovich and Seth Jenkins, details a sophisticated **zero-click exploit chain** targeting Google Pixel 9 and Pixel 10 devices. The primary objective was to achieve root access on these modern Android phones with no user interaction, initiated merely by sending a text or RCS message containing a malicious audio attachment. This research highlights critical vulnerabilities across the Android media processing pipeline and kernel drivers, demonstrating how seemingly isolated bugs can be chained together to achieve full system compromise.

AI review

Silvanovich and Jenkins deliver a full-chain, zero-click root exploit against current-generation Pixel hardware — not a proof-of-concept, not a theoretical attack, a working demo with camera exfil. The research is technically dense across every stage: a novel integer overflow in a proprietary closed-source codec, two separate kernel privilege escalation bugs in Pixel-specific drivers, and a suite of creative bypasses against ASLR, KASLR, SELinux, and seccomp. This is the kind of work that redefines what 'modern Android security' means.

Watch on YouTube