Skip to main content

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

0
Critical
Published: 01/14/2026 (01/14/2026, 18:00:00 UTC)
Source: Google Project Zero

Description

A set of three vulnerabilities were discovered in the BigWave driver on the Pixel 9 device, which is accessible from the mediacodec sandboxed context. One of these bugs enables a use-after-free condition that allows escaping the mediacodec sandbox and achieving arbitrary kernel read/write on the Pixel 9. The vulnerabilities were fixed on January 5, 2026. The BigWave driver accelerates AV1 decoding and is exposed to userland processes in the mediacodec SELinux context, which is intended to be constrained. The use-after-free arises from a race condition between ioctl processing and a worker thread handling hardware jobs, leading to a kernel object being freed while still referenced.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:59:40 UTC

Technical Analysis

The BigWave hardware driver on the Pixel 9 SOC, accessible from the mediacodec SELinux context, contains three vulnerabilities discovered through code auditing. The most critical is a use-after-free (UAF) bug caused by a race condition between the ioctl BIGO_IOCX_PROCESS call and the bigo_worker_thread processing jobs. When the ioctl times out waiting for job completion, it dequeues the job and returns to userland. If the file descriptor is closed at this point, the kernel struct 'inst' containing the job is freed while the worker thread may still access it, leading to UAF and arbitrary kernel read/write capabilities. This bug allows sandbox escape from mediacodec to kernel privilege escalation on Pixel 9 devices. The vulnerabilities were publicly disclosed and fixed on January 5, 2026.

Potential Impact

Successful exploitation of the use-after-free vulnerability in the BigWave driver allows an attacker to escape the mediacodec sandbox and gain arbitrary kernel read and write capabilities on the Pixel 9 device. This results in local privilege escalation, potentially enabling full control over the device kernel and bypassing security restrictions intended by the sandbox. The other two bugs discovered also contribute to the overall risk but are less detailed in the provided information.

Mitigation Recommendations

Fixes for all three vulnerabilities in the BigWave driver were made available on January 5, 2026. Users and administrators should apply the official patches provided by the vendor to remediate these issues. Since this is a local privilege escalation vulnerability in device drivers, updating the Pixel 9 device firmware or operating system to the patched version is the recommended mitigation. No alternative mitigations are described in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://projectzero.google/2026/01/pixel-0-click-part-2.html","fetched":true,"fetchedAt":"2026-08-04T12:57:56.509Z","wordCount":2421}

Threat ID: 6a71e1d4bf8831d539d38873

Added to database: 08/04/2026, 12:57:56 UTC

Last enriched: 08/04/2026, 12:59:40 UTC

Last updated: 09/17/2026, 22:27:56 UTC

Views: 62

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses