Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks
Google has released the January 2026 Android Security Bulletin, advising users to update to the 2026-01-05 patch level or later. This update addresses a critical vulnerability in Dolby components.
Google has released the January 2026 Android Security Bulletin, advising users to update to the 2026-01-05 patch level or later. This update addresses a critical vulnerability in Dolby components.
The primary concern, identified as CVE-2025-54957, affects the Dolby Digital Plus (DD+) codec. It involves an out-of-bounds memory write vulnerability in Dolby’s Universal Decoder Core (UDC) versions 4.5 through 4.13. This issue is triggered when processing a specially crafted DD+ bitstream that appears valid but is non-standard.
Although legitimate Dolby authoring tools do not produce such streams, there is a report involving Google Pixel devices where this vulnerability is exacerbated when combined with other known vulnerabilities specific to Pixel devices.
Google warns that other Android devices could also be at risk. For non-Pixel hardware, exploitation typically results in a media player crash or device restart, indicating a low risk for independent malicious use. Dolby has rated the severity as Critical, and patches are being deployed. AOSP source code updates are expected within 48 hours of the bulletin's release.
Google has released the January 2026 Android Security Bulletin, advising users to update to the 2026-01-05 patch level or later.
Google emphasizes the importance of its layered defenses, including exploit mitigations and Google Play Protect, which scans for potentially harmful apps in real-time. Play Protect is enabled by default on Google Mobile Services (GMS) devices and has successfully blocked numerous threats.
Users are encouraged to check their device’s security patch level by navigating to Settings > About phone > Android version and to prioritize installing updates, especially Pixel users. It is also recommended to download apps exclusively from Google Play to benefit from Play Protect.
Although no active exploits have been confirmed, this patch addresses multiple issues, with Dolby being a primary focus. The security team continues to monitor the situation through Play Protect telemetry.
Based on reporting by Cyber Security News.
