Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Apple
  5. Mobile
  6. News

Researchers find serious exploits in Samsung, Apple and Huawei phones

Add as a preferred source on Google

If you own an iPhone 7 or Galaxy S8, you may want to check for updates. This week, Zero Day Initiative (ZDI) hosted its annual Pwn2Own contest in Tokyo as researchers from around the world gathered to show exploits on the iPhone 7, Samsung S8, and Huawei Mate 9 Pro.

This year’s event yielded 32 different vulnerabilities and awarded $515,000 in payments to researchers.

Recommended Videos

iPhone

iPhone X v iPhone 6S opinion 6s in hand
Image used with permission by copyright holder

Qihoo 360 Security exposed a vulnerability where hackers could use Wi-Fi to execute code on an iPhone 7. They also were able to exploit Safari through a bug in the browser and one in system services.

Tencent Keen Security Lab exposed a troubling Wi-Fi exploit where hackers could use a series of bugs to gain execution and escalate privilege on the iPhone 7 to install a rogue app. The app remained on the device even after a restart. 

Fluorescence (Richard Zhu) exploited a bug in the iPhone 7’s Safari browser with an out-of-bounds bug to escape the browser’s sandbox and execute code on the phone.

Samsung

Image used with permission by copyright holder

MWR Labs exposed a serious vulnerability on the Samsung Galaxy S8. The researchers used 11 vulnerabilities across six different applications to execute code and pull data from the device. This magnitude of bugs allowed the researchers to continue exploiting the phone even after a reboot.

Qihoo 360 Security used the Samsung internet browser on the Galaxy S8 to run code and then leveraged a privilege escalation in a Samsung application that persisted through a device reboot.

Huawei

Huawei Mate 9 review Huawei Mate 10
Andy Boxall/Digital Trends
Andy Boxall/Digital Trends

MWR Labs used a series of five bugs in different Huawei applications to escape the Google Chrome browser sandbox and remove data from a Huawei Mate 9 Pro.

Tencent Keen Security used a Huawei Mate 9 Pro to showcase the most devastating vulnerability during the contest. The researchers were able to execute a baseband attack on the device and execute code on the broadband processor.  They were then able to modify the device’s International Mobile Equipment Identity (IMEI), something that could cause huge disruptions if it was done in the wild.  This was the first broadband exploit ever submitted to ZDI.

Each year ZDI holds the Pwn2Own contest not only to show device exploits but to give vendors an opportunity to fix them. Exploits are provided to vendors, which are able to ask researchers directly any questions they may have. ZDI then gives the vendor 90 days to correct the issue. If the vendor is unable or does not fix the issue or provide a reasonable statement as to why the vulnerability is not fixed, ZDI publishes an advisory with additional details about the exploits in an effort to protect the public.

Steven Winkelman
Former Staff Writer, Mobile
Steven writes about technology, social practice, and books. At Digital Trends, he focuses primarily on mobile and wearables…
Google’s AI-powered Dreambeans app is now available to everyone in the U.S.
Google’s personalized story app is now available to all eligible U.S. accounts, and can pull context from Gemini alongside Gmail, Calendar, Photos, Search, and YouTube.
Google Dreambeans experimental app featured image

Google’s Dreambeans app is now available to all eligible Google accounts in the U.S. on Android and iOS. The wider rollout comes three months after the Google Labs experiment first launched for AI Ultra subscribers.

For those unaware, Dreambeans creates a small collection of personalized stories (similar to Instagram stories) each day based on information from Google services selected by the user. Google had already started removing the subscription requirement in August, and the latest expansion completes that rollout for everyone aged 18 and older in the U.S.

Read more
Theft prevention system can be exploited to block your new phone or disable home alarms
home-security-system

The system built to stop stolen phones from working could actually be turned against you. Michigan State University researchers just found six security flaws in the lost and stolen device reporting process, the same one carriers use to blacklist phones by their unique IMEI number.

Turns out an attacker doesn't need to steal your phone to block it. They just need to exploit weak identity checks in how carriers verify who's filing the report.

Read more
iPhone Duo vs. Galaxy Z Fold 8: Apple prioritizes software polish; Samsung leads with engineering experience
One hides the crease, the other hides in your pocket.
iPhone Duo and galaxy z fold 8

Apple’s first foldable, the iPhone Duo, is one of the best first-generation foldables I’ve seen in a while, though that’s also because almost every other major smartphone manufacturer has one and Apple is exceptionally late to the party. Arriving roughly two months after the Samsung Galaxy Unpacked event, the Duo, through no fault of its own, competes directly with the Galaxy Z Fold 8. 

Given that the phones share a similar design philosophy and price bracket, you’re bound to ask which one is the better pick between the two. In this comparison, I’ve tried to break that down, focusing on the practical aspects that shape your day-to-day experience with foldables rather than the spec sheet. Take a look at the hardware differences below, then dive into the real-world differences.

Read more