What is CVE-2025-54957?
CVE-2025-54957 is a 0-click vulnerability in the Dolby decoding process on Google Pixel devices, allowing remote code execution without user interaction. It affected all Android versions until patched in January 2026, making updates critical to mitigate the risk.
Azərbaycanca: CVE-2025-54957, Google Pixel cihazlarda Dolby deşifrələmə prosesində sıfır kliklə (0-click) istismara imkan verən zəiflikdir. Hücumçu heç bir istifadəçi qarşılıqlı əlaqəsi olmadan uzaqdan kod icrası həyata keçirə bilər. 2026-cı ilin yanvarında yamaq buraxılana qədər bütün Android versiyaları təsirlənmişdi, cihazları güncəlləmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: Dolby, Google
FAQ2
Does exploiting CVE-2025-54957 require any user interaction?
No, CVE-2025-54957 allows for 0-click exploitation. This means an attacker can achieve remote code execution (RCE) without any user interaction.
When was the patch for CVE-2025-54957 released?
The patch for CVE-2025-54957 was released in January 2026. Until that date, all Android versions were affected by the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.