PT-2025-42572 · Google+3 · Pixel+3

CVE-2025-54957

·

Published

2025-10-14

·

Updated

2026-08-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolby UDC versions 4.5 through 4.13
Description An out-of-bounds write exists in the Dolby Unified Decoder (UDC) when processing malformed Dolby Digital Plus (DD+) bitstreams. The issue occurs in evo priv.c during the processing of Evolution data, where an integer wraparound during length calculation results in an undersized buffer allocation. This renders subsequent out-of-bounds checks ineffective, allowing memory corruption. This flaw can be exploited as a zero-click vector on Android devices because audio messages and attachments are decoded locally. In real-world exploit chains, this has been used to achieve initial code execution within the mediaserver process by manipulating syncframe offsets and overwriting the dap cpdp init function pointer to bypass Pointer Authentication Codes (PAC) protections.
Recommendations Update Dolby UDC to a version later than 4.13. As a temporary mitigation, restrict the processing of untrusted DD+ audio bitstreams.

Fix

LPE

DoS

RCE

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13252
CVE-2025-54957

Affected Products

Android
Pixel
Samsung
Windows