CERT-In Urges Android Users to Update Smartphones After Google Patches Critical Dolby Vulnerability

The Zero-Click Dolby Digital Plus vulnerability was first reported in October 2025.

Advertisement
Written by Dhruv Raghav, Edited by David Delima | Updated: 14 January 2026 18:15 IST
Highlights
  • Google fixed the Dolby vulnerability earlier this month
  • The issue allowed bad actors to gain remote access to devices
  • The Dolby vulnerability was termed Zero-Click

CERT-In said that the issue was exploited to target individuals and organisations using Android phones.

Photo Credit: Unsplash/ Daniel Romero

Android smartphone owners have been advised by the Indian Computer Emergency Response Team (CERT-In) to download the latest Android update on their handsets. The latest security update from Google fixes a “critical” security flaw related to the Dolby audio bug. First discovered in October 2025, the “Zero-Click” Dolby Digital Plus (DD+) Unified Decoder vulnerability gave unauthorised access to bad actors, who were then able to execute code from their systems. The issue reportedly also impacted Windows devices. With its January security patch, Google has fixed the issue that put the privacy of many Android users at risk.

Why CERT-In Is Urging Android Users to Update Their Smartphones

In its advisory note CIVN–2026-0016, which was issued on Wednesday, the cybersecurity watchdog has advised Android users to download the latest OS update, which patches the “critical” Dolby DD+ Unified Decoder security vulnerability on the phones. CERT-In warned that the said vulnerability could be exploited by hackers and other bad actors to execute “arbitrary” code on the targeted device remotely. Hackers can potentially corrupt the memory systems of the devices of organisations and individuals.

In its January 5 security bulletin, Google announced that its latest January security patch fixes the Dolby components-related vulnerability that was first reported in October 2025. The tech giant, while acknowledging the issue, said that the severity assessment was provided by Dolby.

Advertisement

Additionally, Dolby also issued a security advisory, detailing that an “out-of-bound” write within Dolby's DD+ Unified Decorder version 4.5 and 4.13 could occur while processing a “unique” DD+ bistream. The company also said that it was aware that this particular bug can potentially be exploited to remotely execute code on certain Google Pixel models and other Android devices.

Advertisement

However, at the time of issuing the security advisory, Dolby claimed that the risk of the bug being used for malicious purposes was low. It added that the bug was “most commonly” observed to result in a media player crash or restart.

In October 2025, Google's Project Zero, a group of security researchers, discovered that the Dolby DD+ Unified Decoder bug could be exploited for executing code on an Android device remotely. The researchers dubbed it a zero-click exploit, as it could be run by bad actors without requiring the victim to click on a link or open a media file.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Android, Google, Cybersecurity, CERT In
Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Reveals Deals on Phones For its Upcoming Sale: See Offers
  2. Here's How Much the Motorola Signature Could Cost in India
  3. Here Are the Top 10 Deals on Smartphones During the Upcoming Amazon Sale
  4. This Realme P Series Phone Could Be Launched in India Soon
  5. Nothing Phones Will Get More Expensive in 2026
  6. CERT-In Wants You to Update Your Android Phone After Google Fixes This Flaw
  7. Amazon Great Republic Day Sale 2026: Here Are the Top Deals on Laptops
  8. OnePlus Mid-Size Performance Phone With 8,000mAh Battery Could Launch Soon
  9. Redmi Note 15 Pro 5G India Variant Spied on Geekbench, Could Launch Soon
  10. Google Pixel 10a Launch Timeline, Colourways and Storage Options Leaked
  1. Redmi Note 15 Pro 5G India Launch Seems Imminent After Smartphone Appears on Geekbench
  2. Battlefield 6 Season 2 Delayed to February as EA Extends Season 1
  3. CERT-In Urges Android Users to Update Smartphones After Google Patches Critical Dolby Vulnerability
  4. Apple Led Market as Global Smartphone Shipments Rose 2.3 Percent YoY in Q4 2025 Despite Growing Memory Shortage: IDC
  5. Red Magic 11 Air Design, Colour Options and Display Features Confirmed
  6. Motorola Signature Box Price in India, Launch Date Leaked Ahead of Arrival: Expected Specifications
  7. Dhandoraa Now Streaming on Prime Video: Know Everything About This Telugu Drama Film Online
  8. Oppo 6t Series, Oppo A6 4G, Oppo A6x 4G Specifications, Colourways Listed Online; Could Launch Soon
  9. Samsung Galaxy S26 Leak: Base Model Could Finally Get 45W Fast Charging Upgrade
  10. Haier H5E Series 4K Smart Google TVs With Bezel-Less Design Launched in India: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.