Android users in India are being urged to update their smartphones immediately after the Indian Computer Emergency Response Team (CERT-In) flagged a serious security vulnerability affecting devices running Google’s operating system. The issue, marked as critical, is linked to a flaw in Dolby’s audio processing component and could allow attackers to remotely execute code on affected phones.
The vulnerability has already been patched by Google as part of its January 2026 Android security update, but CERT-In warns that users who delay installing the update may still be exposed.
ALSO READ: GTA 6 Leaks That Are True! Rockstar's Damage Control Sparks Major Revelations
What Is The Dolby Audio Security Flaw?
The flaw is associated with the Dolby Digital Plus (DD+) Unified Decoder, a component used for audio playback on Android devices. According to security researchers, the bug enabled what is known as a "zero-click" exploit, meaning attackers could gain access without requiring users to click a malicious link or open a media file.
Once exploited, attackers could run code remotely and gain unauthorised access to device memory, potentially compromising sensitive personal or organisational data. The issue was first reported in October 2025 and was severe enough to trigger alerts across multiple platforms.
Reports suggest the vulnerability was not limited to Android alone and also affected Windows devices, highlighting the broader scope of the issue.
CERT-In’s Advisory And What It Means For Users
In its advisory CIVN–2026-0016, issued on Wednesday, CERT-In advised all Android smartphone owners to install the latest available OS update without delay. The watchdog warned that the vulnerability could be exploited by hackers to execute "arbitrary" code remotely.
CERT-In further cautioned that such exploits could allow attackers to compromise device memory, posing serious risks to both individual users and organisations relying on Android smartphones for work-related tasks.
Google And Dolby Respond To The Issue
Google confirmed in its January 5 security bulletin that the vulnerability related to Dolby components had been fixed. The company noted that the severity assessment for the issue was provided by Dolby itself.
Dolby also released a separate security advisory, stating that DD+ Unified Decoder versions 4.5 and 4.13 may have an "out-of-bounds" write vulnerability when processing a "unique" DD+ bistream. According to Dolby, the flaw could be exploited to remotely execute code on certain Google Pixel models and other Android devices.
Nevertheless, Dolby played down the chances of actual attacks and said that "while the chances of exploitation are low," the bug "most commonly causes media player crashes or restarts."
Discovery Of The Vulnerability
The bug was first discovered by the Project Zero team at Google in October 2025. The zero-click exploit was considered dangerous by the researchers because it was able to operate without the need for any interaction from the end user, unlike typical malware attacks.
ALSO READ: Vivo V70 Series To Launch In India Soon: Check Out Expected Specs, Features And Price
Those Using Android Should Do It Now
CERT-In's guideline regarding this is very clear: immediately update your device with the latest security update for Android when it becomes available for your device.
