Vulnerability Management, Patch/Configuration Management

Critical Dolby audio decoder bug patched in latest Android update

(Adobe Stock)

Security Affairs reports that Google has issued a universal Android update addressing the critical Dolby audio decoder vulnerability, tracked as CVE-2025-59457, after initially fixing the issue in Pixel phones last month.

Abusing the out-of-bounds write issue, which could arise from Dolby Digital Plus decoder processing of a unique DDPlus bitstream, could present a significant zero-click threat to Android devices, especially if used alongside other vulnerabilities, according to an advisory from Google Project Zero.

"When a file is processed by Dolby's DDPlus Unified Decoder, an out of bounds write is possible when the evolution data is processed. The decoder writes evolution information into a large, heap-like contiguous buffer contained by a larger struct, and the length calculation for one write can overflow due to integer wrap. This leads to the 'allocated' buffer to be too small, and the out-of-bounds check of the subsequent write to be ineffective," said the advisory, which also noted the presence of the bug in macOS.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds