PT-2025-42572 · Google+3 · Pixel+3

Published

2025-10-14

·

Updated

2026-05-20

·

CVE-2025-54957

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolby UDC versions 4.5 through 4.13
Description An out-of-bounds write issue exists in the Dolby Unified Decoder (UDC) audio decoder library, specifically within the Dolby Digital Plus (DD+) component. The flaw occurs when the decoder processes a malformed DD+ bitstream; specifically, when Evolution data is processed by the evo priv.c file, an integer wraparound during length calculation can result in an undersized buffer allocation. This renders subsequent out-of-bounds checks ineffective, allowing memory corruption. This issue can be triggered without user interaction (zero-click) as audio messages and attachments are decoded locally. In real-world exploitation on Android devices, this was used to achieve initial code execution by manipulating syncframe offsets and overwriting the dap cpdp init() function pointer to bypass Pointer Authentication Codes (PAC-RET) protections.
Recommendations Update Dolby UDC to a version later than 4.13. For Android users, apply the January 2026 security update (or December 2025 for Pixel devices). For Windows users, apply the October PatchTuesday updates. Update ChromeOS to the latest available version.

Fix

LPE

RCE

DoS

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13252
CVE-2025-54957

Affected Products

Android
Pixel
Samsung
Windows