PT-2025-42572 · Google +3 · Pixel +3
Published
2025-10-14
·
Updated
2025-11-26
·
CVE-2025-54957
CVSS v3.1
6.5
6.5
Medium
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Dolby UDC and Affected Versions
Dolby UDC versions 4.5 through 4.13
Description
A flaw exists in the Dolby Unified Decoder (UDC) that could allow remote attackers to execute arbitrary code. The issue stems from an out-of-bounds write vulnerability within the DD+ decoder process when processing malformed DD+ bitstreams. Specifically, an integer overflow occurs during the length calculation when processing Evolution data via the
evo priv.c component, leading to a buffer overflow. This allows attackers to overwrite data structures, potentially including pointers, enabling remote code execution. On Android devices, this vulnerability can be exploited remotely without user interaction, as audio messages and attachments are decoded locally by the UDC. A proof-of-concept (PoC) exploit has been demonstrated on Android (Pixel 9, Samsung S24) and macOS devices. The vulnerability is tracked as CVE-2025-54957. The vulnerability allows remote attackers to execute arbitrary code and affect the system.Recommendations
Update to a newer version of Dolby UDC that contains a fix for this vulnerability.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-13252
CVE-2025-54957
Affected Products
Android
Pixel
Samsung
Windows
References · 21
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-54957 · Security Note
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-54957 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-54957 · Security Note
- https://bdu.fstec.ru/vul/2025-13252 · Security Note
- https://t.me/true_secator/7549 · Telegram Post
- https://reddit.com/r/Action1/comments/1ouh4cf/patch_tuesday_november_2025 · Reddit Post
- https://t.me/cveNotify/139411 · Telegram Post
- https://twitter.com/CCBalert/status/1980708846742958111 · Twitter Post
- https://t.me/CVEtracker/35303 · Telegram Post
- https://professional.dolby.com/siteassets/pdfs/dolby-security-advisory-CVE-2025-54957-Oct-14-25.pdf · Note
- https://twitter.com/zeeshankghouri/status/1980121542374601088 · Twitter Post
- https://reddit.com/r/pwnhub/comments/1obj48t/highseverity_dolby_decoder_flaw_opens_door_to · Reddit Post
- https://twitter.com/stooee_/status/1983609879379022283 · Twitter Post
- https://twitter.com/HackingTeam777/status/1981822850550964486 · Twitter Post
- https://twitter.com/CVEnew/status/1980291976873312497 · Twitter Post