HomeSecurityDolby Digital Plus: Vulnerability allows RCE attack

Dolby Digital Plus: Vulnerability allows RCE attack

A new, extremely dangerous “ zero-click ” vulnerability has been discovered in Dolby Digital Plus (DDP) audio decoding software , putting millions of devices – mostly Android – at risk of remote execution of malicious code . The finding, revealed by Ivan Fratric and Natalie Silvanovich of Google’s Project Zero team , demonstrates how even a seemingly harmless audio file can be turned into a cyberattack tool.

Dolby Digital Plus: Vulnerability

The root of the problem: Out-of-bounds write flaw and memory check failure

The vulnerability is located in the DDPlus Unified Decoder, a critical component used to process data in audio formats such as .ec3 and .mp4. The error is related to an out-of-bounds write flaw, leading to incorrect memory allocation (buffer under-allocation).

This means that when the decoder tries to record audio data, it can “overflow” the allowed memory limits, modifying key structures or pointers used by the system. The result? An attacker can execute malicious code remotely, without any action from the user.

See also: PoC exploit released for Linux-PAM vulnerability

Zero-click attacks: The new face of risk

The most concerning aspect of the vulnerability is the lack of user interaction. Android devices, for example, automatically process incoming audio messages through apps like Google Messagesto create transcripts or prepare the file for playback.

This allows attackers to send a specially modified audio file via RCS (Rich Communication Services) — the advanced messaging protocol that replaces traditional SMS. Once received, Android decodes the file in the background, triggering the bug without the user having to open it.

Project Zero researchers have demonstrated that malicious code execution can be achieved simply by sending a file like “dolby_android_crash.mp4” to the target device. The result is the interruption of the C2 (Codec 2.0) process or, in worse cases, the complete compromise of the device.

Dolby Digital Plus: Vulnerability allows RCE attack

Possible impacts and attack scenarios

In real-world scenarios, this vulnerability could be exploited by cybercriminals or state-sponsored groups for stealth attacks. Through phishing campaigns or targeted RCS messages, attackers could install spyware, steal data, or gain remote control of the device.

See also: PoC exploit released for Windows Server Update Services vulnerability

The fact that this is a zero-click attack makes it extremely difficult. The user doesn't see anything suspicious — they don't even have to touch the message. The vulnerability is therefore reminiscent of advanced attacks like the Pegasus spyware, which also exploited media decoders to gain access to systems without user action.

Google's position and disclosure period

Google, following its 90-day Project Zero policy, released the technical details of the bug on September 24, 2025, as the deadline for fixes had expired. While the company has not issued an official statement, it is recommended that all users update their devices , especially messaging apps, immediately.

It has not yet been confirmed whether Google has released a full patch for all Android versions, but the severity of the vulnerability (which affects system functions and not just apps) means that the issue requires firmware-level updates.

Beyond Android: Potential impacts on macOS and other platforms

The researchers also found evidence of the same flaw in versions of Dolby Digital Plus built into macOS and other Dolby-decoding devices, such as smart TVs, soundbars, and media streamers. While macOS's different pre-processing mechanisms appear to mitigate the risk, the finding demonstrates that the problem is cross-platform.

See also: ConnectWise: New serious vulnerabilities in the Automate platform

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Dolby Digital Plus: Vulnerability allows RCE attack

Dolby, as a company, has not yet issued a public statement on the matter, but is expected to release corrective patches in collaboration with device and software manufacturers.

The Irony of DDP: From Sound Enhancement to Attack Vehicle

Dolby Digital Plus was designed to improve audio quality and media data management through Volution Data Management. Ironically, this same technology is now being turned into an exploit, proving that even the most “secure” layers of the media ecosystem can become gateways for malicious activity.

The Dolby DDP case is a reminder that cybersecurity is not limited to software or networks, but extends to every level of the operating ecosystem — even the audio subsystem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS