Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Apple
  5. Mobile
  6. News

Researchers find serious exploits in Samsung, Apple and Huawei phones

Add as a preferred source on Google

If you own an iPhone 7 or Galaxy S8, you may want to check for updates. This week, Zero Day Initiative (ZDI) hosted its annual Pwn2Own contest in Tokyo as researchers from around the world gathered to show exploits on the iPhone 7, Samsung S8, and Huawei Mate 9 Pro.

This year’s event yielded 32 different vulnerabilities and awarded $515,000 in payments to researchers.

Recommended Videos

iPhone

iPhone X v iPhone 6S opinion 6s in hand
Image used with permission by copyright holder

Qihoo 360 Security exposed a vulnerability where hackers could use Wi-Fi to execute code on an iPhone 7. They also were able to exploit Safari through a bug in the browser and one in system services.

Tencent Keen Security Lab exposed a troubling Wi-Fi exploit where hackers could use a series of bugs to gain execution and escalate privilege on the iPhone 7 to install a rogue app. The app remained on the device even after a restart. 

Fluorescence (Richard Zhu) exploited a bug in the iPhone 7’s Safari browser with an out-of-bounds bug to escape the browser’s sandbox and execute code on the phone.

Samsung

Image used with permission by copyright holder

MWR Labs exposed a serious vulnerability on the Samsung Galaxy S8. The researchers used 11 vulnerabilities across six different applications to execute code and pull data from the device. This magnitude of bugs allowed the researchers to continue exploiting the phone even after a reboot.

Qihoo 360 Security used the Samsung internet browser on the Galaxy S8 to run code and then leveraged a privilege escalation in a Samsung application that persisted through a device reboot.

Huawei

Huawei Mate 9 review Huawei Mate 10
Andy Boxall/Digital Trends
Andy Boxall/Digital Trends

MWR Labs used a series of five bugs in different Huawei applications to escape the Google Chrome browser sandbox and remove data from a Huawei Mate 9 Pro.

Tencent Keen Security used a Huawei Mate 9 Pro to showcase the most devastating vulnerability during the contest. The researchers were able to execute a baseband attack on the device and execute code on the broadband processor.  They were then able to modify the device’s International Mobile Equipment Identity (IMEI), something that could cause huge disruptions if it was done in the wild.  This was the first broadband exploit ever submitted to ZDI.

Each year ZDI holds the Pwn2Own contest not only to show device exploits but to give vendors an opportunity to fix them. Exploits are provided to vendors, which are able to ask researchers directly any questions they may have. ZDI then gives the vendor 90 days to correct the issue. If the vendor is unable or does not fix the issue or provide a reasonable statement as to why the vulnerability is not fixed, ZDI publishes an advisory with additional details about the exploits in an effort to protect the public.

Steven Winkelman
Former Staff Writer, Mobile
Steven writes about technology, social practice, and books. At Digital Trends, he focuses primarily on mobile and wearables…
Apple is testing Chinese DRAM even after CXMT refused to cut prices
Apple may be testing CXMT memory for iPhones and MacBooks
iPhone 17 Pro Max

Apple’s search for more memory supply has taken another step forward. The company is now testing DRAM from Chinese manufacturer CXMT across several products, including iPhones and MacBooks, according to The Wall Street Journal. Apple has also held early talks with CXMT about supplying memory for some devices sold in China and is seeking support from the US government before moving ahead.

The timing is particularly interesting. Just recently, we learned that a shortage of DRAM could already be holding up production of the A20 Pro chip expected inside the iPhone 18 Pro. TSMC is said to have around $1 billion worth of finished chips waiting for memory before packaging can continue.

Read more
The Galaxy Z Fold 8 is genuinely cool, but I’d pay up for the Z Fold 8 Ultra
The Ultra costs $200 more than the Fold 8, and I’m ready to pay the premium.
Computer, Electronics, Tablet Computer

Samsung did something genuinely interesting at Galaxy Unpacked 2026. For the first time in the history of its Galaxy Z foldable lineup, it split the book-style foldable line into two entirely different devices. Whether it had something to do with Apple’s purported iPhone Ultra is a conversation for another time, but for now, anyone visiting a Samsung experience center has two Fold phones to choose from: the new Galaxy Z Fold 8 and the Galaxy Z Fold 8 Ultra. 

The Fold 8 is wider, lighter in hand, and built specifically for one-hand use on the cover screen and content consumption on the inner screen. The Fold 8 Ultra, on the other hand, carries forward the tall and thin design. After spending some hands-on time with both devices, I’ve come to a conclusion.

Read more
EU’s Starlink alternative is finally moving beyond the planning stage
IRIS² will provide secure satellite connectivity for European defence, security, and emergency services
IRIS2 satellite constellation

While SpaceX is trying to take on Verizon, AT&T, and T-Mobile with its own mobile network, the European Union is moving in a very different direction. It wants a satellite network it can control itself.

The European Commission and the SpaceRISE consortium have now signed an implementation agreement for IRIS², the EU’s secure satellite connectivity programme. The deal adds another 66 satellites to the project, taking the planned constellation to 348 spacecraft in total. Of those, 330 will operate in low Earth orbit and 18 in medium Earth orbit. First launches are targeted for 2029.

Read more