frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A 0-click exploit chain for the Pixel 10

https://projectzero.google/2026/05/pixel-10-exploit.html
50•happyhardcore•58m ago

Comments

phuff•21m ago
This is a great bug report! I am not a kernel expert by any means even though I have read some about it... 10+ years ago. And I was able to follow along and see what was going on.

It does make me scared for what other dangers lurk since this was a really bad one and it was so little work to find.

Also of note: so many security issues lately have been done using AI. This report makes me think two things:

1. Expertise is still immensely valuable, the more niche, the more valuable.

2. There are lots of niches still where AI doesn't dominate...

shay_ker•8m ago
Hmmm... I'd like someone to double check my thinking here. I posted this exact prompt for gpt 5.5 xhigh:

```

does this look right to you? don't do any searches or check memory, just think through first principles

static int vpu_mmap(struct file fp, struct vm_area_struct vm) { unsigned long pfn; struct vpu_core core = container_of(fp->f_inode->i_cdev, struct vpu_core, cdev); vm_flags_set(vm, VM_IO | VM_DONTEXPAND | VM_DONTDUMP); / This is a CSRs mapping, use pgprot_device */ vm->vm_page_prot = pgprot_device(vm->vm_page_prot); pfn = core->paddr >> PAGE_SHIFT; return remap_pfn_range(vm, vm->vm_start, pfn, vm->vm_end-vm->vm_start, vm->vm_page_prot) ? -EAGAIN : 0; }

```

And it correctly identified the issue at hand, without web searches. I'd love to try something more comprehensive, e.g. shoving whole chunks of the codebase into the prompt instead of just the specific function, but it seems the latent ability to catch security exploits is there.

So then.... I wonder how this got out in the first place. I know I'm using a toy example but would love to learn more!

greesil•8m ago
"This is notably fast given that this is the first time that an Android driver bug I reported was patched within 90 days of the vendor first learning about the vulnerability."

This makes me feel better about Google, but also makes me kind of frightened of the rest of Android. I wonder what Apple's response time is?

NooneAtAll3•8m ago
fascinating how GrapheneOS achieves high security level on the same hardware where Google failed to even randomize android's kernel location
icf80•2m ago
google has lost its focus with pixel phones
revolvingthrow•7m ago
Semi-related: has the rate of published exploits picked up as if late, or is it simply the fact that there’s hype around ai as security tool (offense or defense) so it’s simply in the news more often?

Feels like there’s something new every other day - linux, windows, mobile, various commonplace tools used by everybody, the list goes on

codedokode•6m ago
I read about Pixel 9 Dolby Decoder bug, and it is based on integer overflow. It was a mistake to allow "+" operator to overflow, and this must be fixed in new languages like Rust, but it is not.

The Underground Market That Unlocks Stolen iPhones

https://www.infoblox.com/blog/threat-intelligence/lookalike-domains-expose-the-iphone-theft-economy/
1•speckx•1m ago•0 comments

Centralized Dead-Letter Queue for Easy Troubleshooting of Distributed Systems

https://carlosblanco.github.io/architecture/backend/2026/05/15/event-driven-architecture-troubles...
1•carlosomar2•2m ago•0 comments

Dear bartending, I still love you

https://spicymelonblog.com/dear-bartending-i-still-love-you/
1•aralsamuel•2m ago•0 comments

Typograms: A portable ASCII diagram format that renders to SVG

https://google.github.io/typograms/
1•matijash•4m ago•0 comments

Tech Layoff Wave Has Hit 100k Jobs This Year

https://www.statista.com/chart/36198/tech-and-startup-employees-laid-off-worldwide/
1•speckx•4m ago•0 comments

Earth is flying through ancient supernova dust

https://www.sciencedaily.com/releases/2026/05/260513221751.htm
1•flockyflock•5m ago•0 comments

Django LiveView vs. Phoenix LiveView: a real benchmark

https://en.andros.dev/blog/80134668/django-liveview-vs-phoenix-liveview-a-real-benchmark/
1•andros•6m ago•0 comments

GitLab is betting a 19th-century economic theory will shape its AI era

https://thenewstack.io/gitlab-ai-agents-jevons-paradox/
1•Brajeshwar•7m ago•0 comments

Show HN: CtxVault – receipts for AI context, not another memory store

https://ctxvault.github.io/ctxvault/
1•LuxBennu•8m ago•0 comments

Show HN: Cchost – Run multiple isolated Claude Code accounts on one machine

https://github.com/allenhack638/cchost
1•allenbenny038•8m ago•0 comments

TypeScript Refactoring Interview Questions

https://reactdevelopment.substack.com/p/typescript-refactoring-interview
1•javatuts•11m ago•0 comments

Mental bugs due to lack of imagination

https://nahurst.substack.com/p/mental-bugs-due-to-lack-of-imagination
2•nathanh•16m ago•0 comments

Show HN: Formal Verification with Lean

https://www.daniellowengrub.com/blog/2026/04/30/lean
1•lowdanie•20m ago•0 comments

Digital Twin – An AI Clone of Yourself (Claude and ElevenLabs and Cloudflare)

https://aimirrortwin.com
1•sumhead•20m ago•1 comments

Zig vs. Rust in 2026

https://zackoverflow.dev/writing/zig-vs-rust-in-2026/
3•ibobev•22m ago•0 comments

Microsoft and Apple bets on new mascots in bid to seem more cuddly

https://www.bbc.com/news/articles/c99l1zzp8xzo
1•reconnecting•23m ago•0 comments

Kicking the Tyres on Harbor for Agent Evals

https://rmoff.net/2026/04/09/kicking-the-tyres-on-harbor-for-agent-evals/
1•eigenBasis•24m ago•0 comments

There's a $50B company hiding inside Salesforce

1•emmanol•24m ago•0 comments

Recursant, the open source AI control plane, now supports OpenClaw

https://clawhub.ai/plugins/openclaw-recursant
1•hestefisk•25m ago•0 comments

From latency to instant: Modernizing GitHub Issues navigation performance

https://github.blog/engineering/architecture-optimization/from-latency-to-instant-modernizing-git...
1•Brajeshwar•25m ago•0 comments

Ask HN: What AI tools are you using every day?

1•tomchui157•26m ago•3 comments

Introducing Spend Caps (Google Cloud)

https://cloud.google.com/blog/topics/cost-management/introducing-spend-caps-ai-cost-visibility-ne...
1•markerbrod•29m ago•0 comments

Check Your Fucking Sources, People

https://brodzinski.com/2026/05/check-fcking-sources.html
7•flail•30m ago•0 comments

Our response to the TanStack NPM supply chain attack

https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/
1•taubek•30m ago•0 comments

The SGI Buyer's Guide

https://hardware.majix.org/computers/sgi/buyers-guide.shtml
1•uticus•32m ago•1 comments

Crypto-Agility Is a Runtime Property, Not a Compliance Checkbox

https://mayckongiovani.substack.com/p/pqc-engineering-series-deep-dive-8f2
1•doomhammerhell•33m ago•0 comments

C++26: Standard Library Hardening

https://www.sandordargo.com/blog/2026/05/13/cpp26-library-hardening
1•ibobev•34m ago•0 comments

ASCII by Jason Scott

https://ascii.textfiles.com/
14•bookofjoe•35m ago•2 comments

Zerodep (2023)

https://philipbohun.com/blog/0003.html
1•vinhnx•37m ago•0 comments

Mkjwk: Simple JSON Web Key Generator

https://mkjwk.org/
2•mooreds•37m ago•0 comments