Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.
David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.
The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.
They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.
Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.
These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.
// Seth Jenkins SOCIAL //
LinkedIn: / seth-jenkins-a20b914b
X: https://x.com/__sethJenkins
// Natalie Silvanovich SOCIAL //
X: https://x.com/natashenka?lang=en
Website: https://natashenka.ca/
// Website REFERENCE //
Google Project Zero website: https://projectzero.google/
// David’s Social //
================
Coect with me:
================
Discord: http://discord.davidbombal.com
X: https://www.x.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube Main https://www.youtube.com/davidbombal
YouTube Tech: https://www.youtube.com/chael/UCZTIRrENWr_rjVoA7BcUE_A
YouTube Clips: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Emerging Technologies: https://www.youtube.com/chael/UCbY5wGxQgIiAeMdNkW5wM6Q
YouTube Shorts: https://www.youtube.com/chael/UCEyCubIF0e8MYi1jkgVepKg
Apple Podcast: https://davidbombal.wiki/applepodcast
Spotify Podcast: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: / davidbombal
================
Support me:
================
Or, buy my CCNA course and support me:
DavidBombal.com: CCNA ($10): http://bit.ly/yt999ccna
Udemy CCNA Course: https://bit.ly/ccnafor10dollars
GNS3 CCNA Course: CCNA ($10): https://bit.ly/gns3ccna10
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 – Intro
01:00 – ThreatLocker sponsor segment
02:10 – Natalie Silvanovich background
04:00 – Seth Jenkins background
04:49 – Zero click audio codec vulnerability
05:41 – Disclaimer
06:07 – Hacking using audio files // How it works
10:23 – What happens in the sandbox
13:27 – The next step
15:15 – Running into issues
22:55 – Would someone notice the hack?
26:20 – Not secure by default
27:44 – Using AI assistance
29:44 – How to reduce attack surface
34:57 – How to get into cybersecurity
39:05 – Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#google #bhusa2026 #pixel10












