
technologySep 8, 202639:19failed
#601: Google Researchers Hacked the Pixel Phone using Audio Messages
About this episode
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.
David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.
The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.
They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.
Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.
These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.
// Seth Jenkins SOCIAL //
LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/
X: https://x.com/__sethJenkins
// Natalie Silvanovich SOCIAL //
X: https://x.com/natashenka?lang=en
Website: https://natashenka.ca/
// Website REFERENCE //
Google Project Zero website: https://projectzero.google/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
// MENU//
0:00 - Intro
01:00 - ThreatLocker sponsor segment
02:10 - Natalie Silvanovich background
04:00 - Seth Jenkins background
04:49 - Zero click audio codec vulnerability
05:41 - Disclaimer
06:07 - Hacking using audio files // How it works
10:23 - What happens in the sandbox
13:27 - The next step
15:15 - Running into issues
22:55 - Would someone notice the hack?
26:20 - Not secure by default
27:44 - Using AI assistance
29:44 - How to reduce attack surface
34:57 - How to get into cybersecurity
39:05 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#google #bhusa2026 #pixel10
Get every episode summarized
Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from David Bombal

#603: How Age Verification Threatens Your Online Privacy
David Bombal
Sep 8, 202647:37failed

#602: How Compilers Turn Secure C Code Into Vulnerable Binaries
David Bombal
Sep 8, 202630:39failed

#600: This Free Tool Decodes Game Boy ROM From a Photograph
David Bombal
Sep 2, 202641:33pending

#599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds
David Bombal
Sep 2, 202642:32pending