Avatar for hazelnoot
Note
1/18/2026, 2:15:38 PM
Avatar for hazelnoot
@hazelnoot
Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones.
are you kidding me
Avatar for natashenka@infosec.exchange
Natalie Silvanovich
@natashenka@infosec.exchange
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices.

https://projectzero.google/2026/01/pixel-0-click-part-1.html
Avatar for skirmisher@snoot.tube
Will
💜
@Skirmisher@snoot.tube
Avatar for hazelnoot@enby.life
@hazelnoot
my favorite commentary on the series (lampshading the fact that Project Zero is part of Google) comes from LWN's brief-as-ever linkback:
The blog entry does not question the wisdom of directly exposing audio decoders to external attackers, [...]
Avatar for kats@chaosfem.tw
Kat S
@KatS@chaosfem.tw
Avatar for hazelnoot@enby.life
@hazelnoot
Cue "I remember when Google was a respected name in software engineering."
Avatar for ncrazed@fd00.space
Edvin Malinovskis
@nCrazed@fd00.space
Avatar for hazelnoot@enby.life
@hazelnoot
does this mean that using a different SMS app mitigates it?
👀
Avatar for hazelnoot
Hazelnoot
@hazelnoot
Avatar for ncrazed@fd00.space
@nCrazed@fd00.space
potentially, but only partially. Clicking on a malicious image can still trigger the underlying vuln, which exists within the OS rather than any particular app.
Avatar for leeloo@chaosfem.tw
Leeloo
@leeloo@chaosfem.tw
Avatar for hazelnoot@enby.life
@hazelnoot

Outlook Express? Is that you?
Avatar for pixx@merveilles.town
pixx
@pixx@merveilles.town
Avatar for hazelnoot@enby.life
@hazelnoot
Avatar for catsalad@infosec.exchange
@catsalad@infosec.exchange


I - wait, what's the maximum audio size per attachment, and max attachments per message? Could you plausibly send enough data to fuck with someone's battery life?
🤔
@kevinrns@mstdn.social has been silenced by enby.life staffmstdn.social has been silenced by enby.life staff
hachyderm.io has been silenced by enby.life staff
Avatar for whimsy@beige.party
Whimsy
@Whimsy@beige.party
Avatar for hazelnoot@enby.life
@hazelnoot


I have no idea what this means. I’m thinking nothing good.
Avatar for hazelnoot
Hazelnoot
@hazelnoot
Avatar for whimsy@beige.party
@Whimsy@beige.party
ah, to paraphrase in normal language:

Google, attempting to speed up fancy features in their Messages app, allowed the app to automatically read messages and analyze media attachments before the user ever actually opens them. This allows hackers to exploit software vulnerabilities silently instead of needing to trick a user into viewing a malicious message. In effect, they chose to reduce the phone's security in order to make the assistant features run faster.
Avatar for whimsy@beige.party
Whimsy
@Whimsy@beige.party
Avatar for hazelnoot@enby.life
@hazelnoot


oh goodness. I use Signal currently. I hope they don't do that.
Avatar for 2something@transfem.social
2something
@2something@transfem.social
Avatar for hazelnoot@enby.life
@hazelnoot
Does this apply if I use Fossify Messages or only if I use the Google Messages app?
Avatar for hazelnoot
Hazelnoot
@hazelnoot
Avatar for 2something@transfem.social
@2something@transfem.social
the attacks work against any app, but it's much harder to exploit with a different messaging app.

Specifically, it requires up to 256 messages to be opened and the attachments viewed - and you're likely to just block the attacker after one or two. But with google messages, the app will quietly open the messages for you in the background - making it way easier to pull off.
Avatar for autisticplushy@lgbtqia.space
Au Ti Va Volade
:v_enby:
@autisticplushy@lgbtqia.space
Avatar for 2something@transfem.social
@2something@transfem.social
Avatar for hazelnoot@enby.life
@hazelnoot
i dont think fossify uses Google RCS protocol
Avatar for 2something@transfem.social
2something
@2something@transfem.social
Avatar for autisticplushy@lgbtqia.space
@autisticplushy@lgbtqia.space
Avatar for hazelnoot@enby.life
@hazelnoot
I don't think it supports RCS at all, but I am worried since the linked article also mentions SMS.
Avatar for hazelnoot
Hazelnoot
@hazelnoot
Avatar for 2something@transfem.social
@2something@transfem.social
yeah - RCS isn't required for the vulnerability described, or for attacking other zero-click vulns that may exist in the media code. The issue seems to be the messages app itself rather than any particular protocol.
hachyderm.io has been silenced by enby.life staff
Avatar for aperture@snug.moe
Aprettyture! [0172]
@aperture@snug.moe
Avatar for hazelnoot@enby.life
@hazelnoot
im not even like a programmer and i know how catastrophically stupid that is

-carrie
hachyderm.io has been silenced by enby.life staff
chaos.social has been silenced by enby.life staff