WTF Is a 0-Click? The Dolby Android Bug That Needed No Tap From the Victim

D. Rose · 18 August 2026 · 6 min

One of the most dangerous misconceptions in security is: “I didn't click anything, so how could my phone have processed the attack?”

One of the most dangerous misconceptions in security is: “I didn't click anything, so how could my phone have processed the attack?”

The answer is that modern devices constantly process data before you touch it.

In 2025–2026, Google Project Zero demonstrated this with an Android exploit chain beginning in the Dolby Unified Decoder Codec: an incoming audio message could reach vulnerable decoding code automatically because features such as transcription processed the media before user interaction.

That is what makes a 0-click attack surface.


The 30-Second Version

A normal phishing mental model is:

attacker sends link
victim taps link
malicious content loads
exploit

A 0-click model is:

attacker sends content
phone automatically parses content
vulnerable parser runs
exploit triggers

The user does nothing.

Project Zero found that incoming audio messages on Android could be decoded by components involved in Google Messages transcription/search behavior before the recipient interacted with the message.

A memory-corruption bug in the Dolby decoder could therefore become remotely reachable.

Project Zero then chained that initial bug with a separate kernel/driver vulnerability on Pixel 9 to go from the remote media-decoding context toward kernel-level privileges.

Only two software defects were required for the demonstrated chain.


Part 1: Your Phone Does Things Before You Ask

Think about an incoming message.

Your phone may automatically:

receive packet
decrypt message
identify media type
generate preview
index content
transcribe audio
scan for spam
make content searchable
show notification

You haven't tapped anything yet.

But a lot of code has already executed.

Every automatic feature adds code to the pre-click attack surface.


Part 2: Parser Bugs Are Perfect 0-Click Candidates

A parser converts complicated untrusted data into something software can use.

Examples:

JPEG decoder
PDF parser
audio codec
video decoder
font renderer
archive decompressor

The attacker controls the input.

The victim's device runs the parser.

That is the basic security setup:

ATTACKER-CONTROLLED BYTES
complex native parser
memory operations

If the parser has a memory-safety bug, the attacker may be able to do more than crash it.


Part 3: WTF Is an Out-of-Bounds Write?

Imagine memory as hotel rooms:

Room 100: your buffer
Room 101: something else
Room 102: something important

Your program is supposed to write only inside Room 100.

An out-of-bounds write is:

write starts in Room 100
keeps going
overwrites Room 101

In real memory, what gets overwritten might be:

object metadata
pointer
length field
control data

With enough control, an attacker may turn memory corruption into code execution.


Part 4: Why Audio Was Being Decoded Automatically

Project Zero highlighted Google Messages audio transcription as part of the 0-click attack surface.

Incoming audio needed to be interpreted before the user listened to it because the device wanted to provide helpful features.

That convenience creates a security tradeoff:

MORE AUTOMATIC PROCESSING
MORE CODE RUNS ON UNTRUSTED INPUT
LARGER 0-CLICK ATTACK SURFACE

This is why Project Zero specifically warned that AI-powered phone features can increase 0-click attack surface: more on-device assistants, transcription, summarization, indexing, vision, and semantic search mean more automatic parsing.


Part 5: Why a Decoder Nobody Uses Can Still Matter

One surprising detail was that the Dolby decoder supported formats that ordinary Android devices might not commonly generate.

So you might think:

“Why would an incoming message ever contain this?”

Because the attacker chooses the incoming data.

The relevant question is not:

Do normal users create this format?

It is:

Will the receiving parser try to decode it if an attacker sends it?

Attack surface depends on what code is reachable, not what normal users typically do.


Part 6: One Bug Usually Isn't Enough

Modern phones use sandboxing.

A media decoder should not normally have full control of the device.

So an exploit chain looks like:

remote media bug
code execution in restricted process
sandbox boundary
second vulnerability
privilege escalation
more powerful control

This is why exploit researchers talk about chains.

Each vulnerability crosses one security boundary.


Part 7: Project Zero's Two-Bug Chain

Project Zero's Pixel 9 work combined:

Dolby decoder vulnerability
0-click entry point
restricted execution context
BigWave driver vulnerability
kernel privileges

The striking point is how short that chain was.

Project Zero explicitly noted that only two software defects were needed to go from a 0-click context to kernel privilege.

Effective sandboxing often forces attackers to collect more bugs.

Every missing isolation layer makes exploitation cheaper.


Part 8: Security Mitigations Add “Exploit Tax”

Modern systems use mitigations such as:

ASLR
sandboxing
seccomp
memory tagging
bounds checks
control-flow protections

A mitigation does not need to make exploitation mathematically impossible.

It can simply add cost.

Project Zero estimated that some missing or ineffective mitigations materially reduced the time required to build its exploit chain.

Think:

Bug exists
mitigation forces attacker
to find another leak / primitive
extra weeks of work

That extra work matters at scale.


Part 9: “Patched” Does Not Mean Every Device Was Instantly Safe

Mobile vulnerability remediation crosses multiple layers:

researcher
component vendor
Android / platform
OEM
carrier / update channel
user device

A bug in a widely integrated third-party codec can affect many manufacturers even though the exploit demonstration targets one Pixel generation.

This is why component inventory matters.


Part 10: 0-Click vs 1-Click

1-click

User must perform an action:

tap link
open document
accept invite

0-click

The vulnerable code runs during automatic handling.

That difference dramatically changes attack quality.

Phishing needs persuasion.

0-click exploitation needs reachability.

No user training can stop a parser from automatically processing a malicious file.


Part 11: Why High-End Spyware Loves 0-Clicks

If you are targeting a journalist, executive, diplomat, or dissident, asking them to click a suspicious link creates risk.

A 0-click is ideal because:

no persuasion
no visible interaction
less victim suspicion
high reliability if chain works

That is why these chains are strategically valuable.


Part 12: The AI Feature Problem

The future phone may automatically:

transcribe every audio message
summarize every notification
OCR every image
classify every attachment
index every conversation
extract entities
generate semantic embeddings

Each feature can cause new libraries to process attacker-controlled content automatically.

AI itself does not magically create the memory bug.

But AI features can make previously dormant parsers remotely reachable before user interaction.

That is the architectural concern.


The Big Misconceptions

“0-click means magic remote hacking with no input.”

No. The attacker still delivers some data; the device automatically processes it.

“If I never opened the message, it couldn't hurt me.”

Not if previews, transcription, indexing, or media decoding happened first.

“The first bug automatically means full phone compromise.”

Usually not. Modern exploit chains often need privilege escalation after initial code execution.

“User security awareness stops 0-click attacks.”

User behavior is largely irrelevant when parsing occurs automatically.


If You Remember Only Five Things

  1. 0-click means the vulnerable code runs before user interaction.
  2. Automatic previews, transcription, indexing, and parsing create attack surface.
  3. Complex media decoders are dangerous because attackers control the bytes.
  4. Sandboxing forces attackers to chain additional vulnerabilities.
  5. Every new automatic AI feature should be evaluated for the code it makes remotely reachable.

Sources & Further Reading