Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

Posted on October 20, 2025October 20, 2025 By CWS

A essential zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software program has been disclosed, permitting attackers to execute malicious code remotely through seemingly innocuous audio messages.

Google Mission Zero’s Ivan Fratric and Natalie Silvanovich have recognized an out-of-bounds write flaw within the DDPlus Unified Decoder, which processes evolution information in audio recordsdata.

This bug stems from an integer overflow in size calculations, resulting in an undersized buffer allocation. In consequence, subsequent writes bypass bounds checks, probably overwriting key struct members, together with pointers processed within the subsequent syncframe.

The difficulty impacts gadgets working the decoder, with extreme implications for Android customers attributable to automated audio processing.

The vulnerability, detailed in a latest bug report, highlights how fashionable messaging apps unwittingly expose customers to distant code execution (RCE). On Android, the flaw allows assaults with none person interplay.

Incoming RCS (Wealthy Communication Companies) audio messages and attachments are decoded regionally for transcription functions, triggering the bug silently within the background.

Potential Exploitation on Android Units

Android gadgets are notably in danger as a result of the Google Messages app and related shoppers use the DDPlus decoder to deal with audio content material proactively.

Attackers might craft malicious audio recordsdata, reminiscent of these in .ec3 or .mp4 codecs, and ship them through RCS. As soon as acquired, the goal’s machine processes the file routinely, probably resulting in a crash within the C2 (Codec 2.0) course of or worse, arbitrary code execution if exploited additional.

Replica is simple for testers: By pushing a specifically crafted file like “dolby_android_crash.mp4” into the messaging app’s cache on a sending machine and initiating an RCS voice message, the goal machine crashes upon receipt.

Researchers supplied pattern bitstreams, together with one which targets 32-bit techniques and one other for 64-bit Android. This ease of exploitation underscores the urgency, as no person motion like opening or taking part in the file is required.

In real-world eventualities, phishing campaigns or focused assaults through messaging might weaponize this for information theft, malware implantation, or machine takeover.

Whereas patches stay unclear as of this report, Android customers are suggested to replace their gadgets and messaging apps promptly. Google has not but commented, however the 90-day disclosure window ended on September 24, 2025, making particulars public.

The flaw extends past Android; code evaluation reveals its presence in macOS implementations, although pre-processing steps might forestall exploitation there.

Researchers are persevering with to probe affected platforms, together with potential impacts on iOS or different Dolby-integrated techniques like good TVs and streaming gadgets.

volution information dealing with in DDP, designed for enhanced audio options, sarcastically turns into a vector for abuse on this case.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0click, Android, Attack, Audio, Digital, Dolby, Enables, Malicious, RCE, Vulnerability

Post navigation

Previous Post: AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More

Related Posts

CISA Warns of Rails Ruby on Rails Path Traversal Vulnerability Exploited in Attacks Cyber Security News
Microsoft Teams Call Weaponized to Deploy and Execute Matanbuchus Ransomware Cyber Security News
New Malware Spotted in The Wild Using Prompt Injection to Manipulate AI Models Processing Sample Cyber Security News
Kali Vagrant Rebuilt Released – Pre-configured DebOS VMs via Command Line Cyber Security News
Darknet Market Archetyp Dismantled by Authorities in Joint Action ‘Operation Deep Sentinel’ Cyber Security News
Threat Actors Using ViperSoftX Malware to Exfiltrate Sensitive Details Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android
  • AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More
  • SIM Farm Dismantled in Europe, Seven Arrested
  • Lumma Stealer Activity Drops After Doxxing
  • ConnectWise Patches Critical Flaw in Automate RMM Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android
  • AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More
  • SIM Farm Dismantled in Europe, Seven Arrested
  • Lumma Stealer Activity Drops After Doxxing
  • ConnectWise Patches Critical Flaw in Automate RMM Tool

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News