Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

Posted on October 20, 2025October 20, 2025 By CWS

A essential zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software program has been disclosed, permitting attackers to execute malicious code remotely through seemingly innocuous audio messages.

Google Mission Zero’s Ivan Fratric and Natalie Silvanovich have recognized an out-of-bounds write flaw within the DDPlus Unified Decoder, which processes evolution information in audio recordsdata.

This bug stems from an integer overflow in size calculations, resulting in an undersized buffer allocation. In consequence, subsequent writes bypass bounds checks, probably overwriting key struct members, together with pointers processed within the subsequent syncframe.

The difficulty impacts gadgets working the decoder, with extreme implications for Android customers attributable to automated audio processing.

The vulnerability, detailed in a latest bug report, highlights how fashionable messaging apps unwittingly expose customers to distant code execution (RCE). On Android, the flaw allows assaults with none person interplay.

Incoming RCS (Wealthy Communication Companies) audio messages and attachments are decoded regionally for transcription functions, triggering the bug silently within the background.

Potential Exploitation on Android Units

Android gadgets are notably in danger as a result of the Google Messages app and related shoppers use the DDPlus decoder to deal with audio content material proactively.

Attackers might craft malicious audio recordsdata, reminiscent of these in .ec3 or .mp4 codecs, and ship them through RCS. As soon as acquired, the goal’s machine processes the file routinely, probably resulting in a crash within the C2 (Codec 2.0) course of or worse, arbitrary code execution if exploited additional.

Replica is simple for testers: By pushing a specifically crafted file like “dolby_android_crash.mp4” into the messaging app’s cache on a sending machine and initiating an RCS voice message, the goal machine crashes upon receipt.

Researchers supplied pattern bitstreams, together with one which targets 32-bit techniques and one other for 64-bit Android. This ease of exploitation underscores the urgency, as no person motion like opening or taking part in the file is required.

In real-world eventualities, phishing campaigns or focused assaults through messaging might weaponize this for information theft, malware implantation, or machine takeover.

Whereas patches stay unclear as of this report, Android customers are suggested to replace their gadgets and messaging apps promptly. Google has not but commented, however the 90-day disclosure window ended on September 24, 2025, making particulars public.

The flaw extends past Android; code evaluation reveals its presence in macOS implementations, although pre-processing steps might forestall exploitation there.

Researchers are persevering with to probe affected platforms, together with potential impacts on iOS or different Dolby-integrated techniques like good TVs and streaming gadgets.

volution information dealing with in DDP, designed for enhanced audio options, sarcastically turns into a vector for abuse on this case.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0click, Android, Attack, Audio, Digital, Dolby, Enables, Malicious, RCE, Vulnerability

Post navigation

Previous Post: AWS Outage Impacts Amazon, Snapchat, Prime Video, Canva and More
Next Post: South Korea Seeks to Arrest Dozens of Online Scam Suspects Repatriated From Cambodia

Related Posts

Critical Flaws in VS Code Extensions Threaten Developers Critical Flaws in VS Code Extensions Threaten Developers Cyber Security News
Django Critical Vulnerability Let attackers Execute Malicious SQL Code on Web Servers Django Critical Vulnerability Let attackers Execute Malicious SQL Code on Web Servers Cyber Security News
WhatsApp Enhances Security with Optional Account Password WhatsApp Enhances Security with Optional Account Password Cyber Security News
New Linux Malware Poses Threat to Software Developers New Linux Malware Poses Threat to Software Developers Cyber Security News
Hackers Use Emoji Code to Evade Security Systems Hackers Use Emoji Code to Evade Security Systems Cyber Security News
Drone Strikes Disrupt AWS Services in UAE Region Drone Strikes Disrupt AWS Services in UAE Region Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations
  • Fragnesia Vulnerability Risks Root Access on Linux Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations
  • Fragnesia Vulnerability Risks Root Access on Linux Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark