Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Playing the clip yourself would only be the one-click route. The exploit's actual significance is the zero-click path, where Google Messages auto-transcribes incoming audio and triggers the Dolby decode without any interaction at all.

A device running a 6+-month-old GrapheneOS version and having Google Messages installed would be vulnerable to that zero-click. The key question is whether and how it could be utilised to get past BFU mode. Maybe they can find another entry point via cellular/WiFi, as very few GOS users will have Google Messages installed anyway. So this might be the first zero-click on GOS, but it's still very speculative, as there is no public PoC. And it matters only for devices that didn't get updates.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: