Back to Blog

Project Zero

5 articles on this topic.

Vulnerability Research9 September 2026

Project Zero's MAccConc: Making Race Conditions Reproducible for Testing

Google Project Zero has released MAccConc, a tool that pairs memory-access tracing with stack-based delay injection to reliably reproduce thread interleavings — turning notoriously flaky race-condition bugs into repeatable test cases.

race-conditionsproject-zerokernel-security
4 min readRead
Vulnerability Research9 July 2026

Project Zero's Redesign Is a Reminder: 2016 Windows Bugs Still Teach

Google Project Zero relaunched its blog and used the moment to republish vulnerability research from 2016 and 2017 — a signal that foundational exploitation techniques haven't gone stale.

project-zerowindows-exploitationvulnerability-research
4 min readRead
Mobile Security8 July 2026

Pixel 9 0-Click Exploit Chain: Dolby Codec Bug Meets AI Transcription

Google Project Zero chained an integer overflow in Dolby's audio decoder with a kernel driver flaw to get zero-click code execution on a Pixel 9 — reached through the auto-transcription feature in Google Messages.

android0-clickmobile-security
4 min readRead
Mobile Security8 July 2026

Pixel 9 0-Click Chain, Part 2: A Codec Bug Reaches the Kernel via /dev/bigwave

Google Project Zero's second installment shows how a sandboxed mediacodec foothold on a Pixel 9 became full kernel read/write through a use-after-free in the BigWave AV1 decoder driver.

androidpixelkernel-exploit
4 min readRead
Windows Internals / Offensive Security5 July 2026

GetProcessHandleFromHwnd: How One Windows API Enabled a Persistent UAC Bypass

Google Project Zero traces a public Quick Assist UAC bypass back to a poorly documented Win32 API that Microsoft only half-fixed in 2023 — and shows why fully protected processes stayed exploitable until Windows 11 24H2.

windows-securityuac-bypassprivilege-escalation
5 min readRead