You are the manager of a vulnerability research team. You are easily distracted and often late for meetings. You forget important emails.
When you join the Stonecutters, you get the real H264 conformance test vectors, that really test all the features
What if Python smelled the flowers? Read a book? Did anything but complain about consistent use of tabs and spaces?
New variation on an old theme: reporting a low severity bug because AI *fixates* on it to the exclusion of other bugs
There’s ‘shrinkwrap’ on this Tamagotchi … sticker
And the Owl said, “If you want to find the maintainer, go to the north side of the pond when the moon is out. Turn yourself around three times, then look into the water to see them.”
Seth Jenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug! We’ll be presenting this work Saturday @offensivecon.bsky.social projectzero.google/2026/05/pixe...
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...
projectzero.google
Big changes to Android and Chrome VRP: - focus on high-impact, reproducible bugs with low/no reward for lower impact - big prizes for full chains with some annual limits - PoCs required It’s the end of an era, but the start of a new one. bughunters.google.com/blog/evolvin...
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
bughunters.google.com
There’s a little piece of my heart that beats just for Spanify groups.google.com/a/chromium.o...
Introducing Spanification
groups.google.com
Amazing work by Meta implementing fast and robust WebRTC updates! “We can’t push updates because …” can often be solved with investment and innovative engineering engineering.fb.com/2026/04/09/d...
Escaping the Fork: How Meta Modernized WebRTC Across 50+ Use Cases
At Meta, WebRTC powers real-time audio and video across various platforms. But forking a large open-source project like WebRTC within our monorepo presents unique challenges – over time, an interna…
engineering.fb.com
Just put a reminder in my calendar for November 1, 2026 to check whether we still have bugs
Mountain View Reverse Engineering (mtvre) meetup on Wed! 7:00 pm at Wagon Wheel BBQ. Talks: - @tubetime.bsky.social on "HP 16717 PCB Reverse Engineering" (40 min) - @natashenka.bsky.social on "0-click Android exploits" (25 min)
Ivan Fratric shares some tips and tricks for grammar fuzzing projectzero.google/2026/03/muta...
On the Effectiveness of Mutational Grammar Fuzzing
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar t...
projectzero.google
In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...
projectzero.google
Part 2 of @tiraniddo.dev’s Windows Administrator Protection journey is here! projectzero.google/2026/02/wind...
Bypassing Administrator Protection by Abusing UI Access - Project Zero
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exi...
projectzero.google
The remarkable true story of how Flash was deprecated medium.com/@aglaforge/w...
What Really Killed Flash Player: A Six-Year Campaign of Deliberate Platform Work
This is what it actually took. From the person who architected and drove Chrome’s Flash deprecation from proposal to the final removal in…
medium.com
Our intrepid 20%-er Dillon Franke exploited a vulnerability in CoreAudio. See his process for gaining privilege escalation on a Mac: projectzero.google/2026/01/soun...
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 - Project Zero
In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-...
projectzero.google
No security feature is perfect. @tiraniddo.dev reviewed Windows’ new Administrator Protection and found several bypasses. projectzero.google/2026/26/wind...
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
projectzero.google
Some extra 0-click fun! Seth Jenkins and I trying to figure out why our exploit isn’t working, when it has, in fact, already started taking and exfiltrating photos
Today, Project Zero released a 0-click exploit chain for the Pixel 9. While it targets the Pixel, the 0-click bug and exploit techniques we used apply to most other Android devices. projectzero.google/2026/01/pixe...
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
projectzero.google
But wait, I haven’t read all the “Best Books of 2024” yet
We launched a redesigned Project Zero website today at projectzero.google ! To mark the occasion, we released some older posts that never quite made it out of drafts. Enjoy!
Google Project Zero
Make zeroday hard
projectzero.google
An analysis of a recent 0-click exploit targeting Samsung devices: googleprojectzero.blogspot.com/2025/12/a-lo...
A look at an Android ITW DNG exploit
Posted by Benoît Sevens, Google Threat Intelligence Group Introduction Between July 2024 and February 2025, 6 suspicious image files were ...
googleprojectzero.blogspot.com
Crime show: “We know the victim died at night because we found beef in his stomach.” Me, shoving a left-over burger in my face at 7am: 🫢
Your phone’s more likely to hit the ASLR state you need if you put a lucky dragon on it