Security25.10.2023

Hacking teams win R1.4 million for exploiting Galaxy S23 zero-day

The Pwn2Own hacking competition in Toronto this year saw two teams successfully exploit zero-day vulnerabilities on Samsung’s Galaxy S23 smartphone, Bleeping Computer reports.

Combined, the two teams earned $75,000 (R1.4 million), and other hacking teams demonstrated exploits and vulnerability chains in Xiaomi’s 13 Pro, as well as printers, smart speakers, and surveillance cameras.

Pentest Limited was the first team to successfully demonstrate a zero-day on the Samsung Galaxy S23 by exploiting improper input validation weaknesses to gain code execution.

They took home $50,000 (R950,000) and five Master of Pwn points for being the first to demonstrate a zero-day for the device successfully.

STAR Labs SG almost successfully demonstrated a zero-day for the device, earning it five Master of Pwn points. However, it only got a $25,000 (R475,000) cash reward.

“While only the first demonstration in a category wins the full cash award, each successful entry claims the full number of Master of Pwn points,” the Pwn2Own organisers said.

“Since the order of attempts is determined by a random draw, those who receive later slots can still claim the Master of Pwn title — even if they earn a lower cash payout.”

In total, $438,750 (R8.4 million) was awarded to teams that successfully demonstrated zero-day vulnerabilities on the first day of the competition.

However, the biggest prizes have yet to come.

Teams can earn a cash prize of up to $300,000 (R5.7 million) for successfully hacking the iPhone 14 and up to $250,000 (R4.8 million) for Google’s Pixel 7.


Now read: Cyberattackers put malware on blockchain to stop removal

Show comments

Latest news

More news

Trending news

Poll

Which company do you use for your home security system?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter