#601: Google Researchers Hacked the Pixel Phone using Audio Messages

#601: Google Researchers Hacked the Pixel Phone using Audio Messages

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device. David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10. The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access. They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones. Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive. These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected. // Seth Jenkins SOCIAL // LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/ X: https://x.com/__sethJenkins // Natalie Silvanovich SOCIAL // X: https://x.com/natashenka?lang=en Website: https://natashenka.ca/ // Website REFERENCE // Google Project Zero website: https://projectzero.google/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU// 0:00 - Intro 01:00 - ThreatLocker sponsor segment 02:10 - Natalie Silvanovich background 04:00 - Seth Jenkins background 04:49 - Zero click audio codec vulnerability 05:41 - Disclaimer 06:07 - Hacking using audio files // How it works 10:23 - What happens in the sandbox 13:27 - The next step 15:15 - Running into issues 22:55 - Would someone notice the hack? 26:20 - Not secure by default 27:44 - Using AI assistance 29:44 - How to reduce attack surface 34:57 - How to get into cybersecurity 39:05 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #google #bhusa2026 #pixel10

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(500)

#608: Before You Deploy AI Agents, Understand These Attacks

#608: Before You Deploy AI Agents, Understand These Attacks

Big thanks to Proton VPN for sponsoring this video. You can use my link: https://protonvpn.com/davidbombal to get 70% off your Proton VPN subscription How do you hack an AI system? And what happens...

19 Sep 52min

#607: How Hackers Steal Your Accounts Even With 2FA Enabled

#607: How Hackers Steal Your Accounts Even With 2FA Enabled

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.thre...

19 Sep 31min

#606: Is Cybersecurity Still Worth Learning in 2026?

#606: Is Cybersecurity Still Worth Learning in 2026?

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker, please use the following link: https://www.thr...

19 Sep 31min

#605: Flock Cameras: What They Can Reveal About Your Life

#605: Flock Cameras: What They Can Reveal About Your Life

Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off. Your license plate could reveal more than you t...

12 Sep 22min

#604: How He Infiltrated LockBit and Helped Get Them Indicted

#604: How He Infiltrated LockBit and Helped Get Them Indicted

Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount. John DiMaggio created fake identities...

12 Sep 24min

#603: How Age Verification Threatens Your Online Privacy

#603: How Age Verification Threatens Your Online Privacy

Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.thre...

8 Sep 47min

#602: How Compilers Turn Secure C Code Into Vulnerable Binaries

#602: How Compilers Turn Secure C Code Into Vulnerable Binaries

Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.t...

8 Sep 30min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-en-ai-till-kaffet
rss-elektrikerpodden
rss-technokratin
rss-ai-med-jonas-benjamin
rss-uppgang-och-fall
rss-sakerhetspodcasten
rss-veckans-ai
rss-snacka-om-ai
bli-saker-podden
developers-mer-an-bara-kod
rss-powerboat-sverige-podcast
rss-it-sakerhetspodden
rss-fabriken-2