A new, extremely dangerous “ zero-click ” vulnerability has been discovered in Dolby Digital Plus (DDP) audio decoding software , putting millions of devices – mostly Android – at risk of remote execution of malicious code . The finding, revealed by Ivan Fratric and Natalie Silvanovich of Google’s Project Zero team , demonstrates how even a seemingly harmless audio file can be turned into a cyberattack tool.

The root of the problem: Out-of-bounds write flaw and memory check failure
The vulnerability is located in the DDPlus Unified Decoder, a critical component used to process data in audio formats such as .ec3 and .mp4. The error is related to an out-of-bounds write flaw, leading to incorrect memory allocation (buffer under-allocation).
This means that when the decoder tries to record audio data, it can “overflow” the allowed memory limits, modifying key structures or pointers used by the system. The result? An attacker can execute malicious code remotely, without any action from the user.
See also: PoC exploit released for Linux-PAM vulnerability
Zero-click attacks: The new face of risk
The most concerning aspect of the vulnerability is the lack of user interaction. Android devices, for example, automatically process incoming audio messages through apps like Google Messagesto create transcripts or prepare the file for playback.
This allows attackers to send a specially modified audio file via RCS (Rich Communication Services) — the advanced messaging protocol that replaces traditional SMS. Once received, Android decodes the file in the background, triggering the bug without the user having to open it.
Project Zero researchers have demonstrated that malicious code execution can be achieved simply by sending a file like “dolby_android_crash.mp4” to the target device. The result is the interruption of the C2 (Codec 2.0) process or, in worse cases, the complete compromise of the device.

Possible impacts and attack scenarios
In real-world scenarios, this vulnerability could be exploited by cybercriminals or state-sponsored groups for stealth attacks. Through phishing campaigns or targeted RCS messages, attackers could install spyware, steal data, or gain remote control of the device.
See also: PoC exploit released for Windows Server Update Services vulnerability
The fact that this is a zero-click attack makes it extremely difficult. The user doesn't see anything suspicious — they don't even have to touch the message. The vulnerability is therefore reminiscent of advanced attacks like the Pegasus spyware, which also exploited media decoders to gain access to systems without user action.
Google's position and disclosure period
Google, following its 90-day Project Zero policy, released the technical details of the bug on September 24, 2025, as the deadline for fixes had expired. While the company has not issued an official statement, it is recommended that all users update their devices , especially messaging apps, immediately.
It has not yet been confirmed whether Google has released a full patch for all Android versions, but the severity of the vulnerability (which affects system functions and not just apps) means that the issue requires firmware-level updates.
Beyond Android: Potential impacts on macOS and other platforms
The researchers also found evidence of the same flaw in versions of Dolby Digital Plus built into macOS and other Dolby-decoding devices, such as smart TVs, soundbars, and media streamers. While macOS's different pre-processing mechanisms appear to mitigate the risk, the finding demonstrates that the problem is cross-platform.
See also: ConnectWise: New serious vulnerabilities in the Automate platform
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Dolby, as a company, has not yet issued a public statement on the matter, but is expected to release corrective patches in collaboration with device and software manufacturers.
The Irony of DDP: From Sound Enhancement to Attack Vehicle
Dolby Digital Plus was designed to improve audio quality and media data management through Volution Data Management. Ironically, this same technology is now being turned into an exploit, proving that even the most “secure” layers of the media ecosystem can become gateways for malicious activity.
The Dolby DDP case is a reminder that cybersecurity is not limited to software or networks, but extends to every level of the operating ecosystem — even the audio subsystem.
