PT-2025-42572 · Google+3 · Pixel+3
Published
2025-10-14
·
Updated
2026-05-20
·
CVE-2025-54957
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dolby UDC versions 4.5 through 4.13
Description
An out-of-bounds write issue exists in the Dolby Unified Decoder (UDC) audio decoder library, specifically within the Dolby Digital Plus (DD+) component. The flaw occurs when the decoder processes a malformed DD+ bitstream; specifically, when Evolution data is processed by the
evo priv.c file, an integer wraparound during length calculation can result in an undersized buffer allocation. This renders subsequent out-of-bounds checks ineffective, allowing memory corruption. This issue can be triggered without user interaction (zero-click) as audio messages and attachments are decoded locally. In real-world exploitation on Android devices, this was used to achieve initial code execution by manipulating syncframe offsets and overwriting the dap cpdp init() function pointer to bypass Pointer Authentication Codes (PAC-RET) protections.Recommendations
Update Dolby UDC to a version later than 4.13.
For Android users, apply the January 2026 security update (or December 2025 for Pixel devices).
For Windows users, apply the October PatchTuesday updates.
Update ChromeOS to the latest available version.
Fix
LPE
RCE
DoS
Integer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android
Pixel
Samsung
Windows