Cyber week deals! Galaxy Watch8 Classic, Fold 7, S25 Ultra. Follow us on YouTube, TikTok, or LinkedIn
Last updated: October 27th, 2023 at 14:40 UTC+02:00
SamMobile has affiliate and sponsored partnerships, we may earn a commission.
Reading time: 2 minutes
On the first day of the event, the Galaxy S23 was successfully attacked through zero-day vulnerabilities two times. Over the course of the next two days, the Galaxy S23 series experienced a few other live hacks.
Story continues after the video
Zero-days are security vulnerabilities of which the OEM, in this case, Samsung, is unaware. Through its Pwn2Own event, ZDI encourages security researchers who demonstrate zero-day exploits to pass the information onto OEMs without publicizing their findings. For their efforts, white hats can win cash prizes.
On the 2nd day of the Pwn2Own event, Interrupt Labs successfully executed an improper input validation attack against the Galaxy S23. In addition, ToChim exploited a permissive list of allowed inputs on the same Samsung flagship.
For demonstrating these two zero-days on the Galaxy S23, each security researcher earned $25,000 and 5 Master of Pwn points.
Moving on to Day 3, Team Orca of Sea Security was able to execute an attack on the Galaxy S23. However, ZDI confirms this bug was previously known. Team Orca won $6,250 and 1.25 Master of Pwn points.
The valuable information gathered by these researchers will likely be used by Samsung (and possibly Google) to develop new security patches. The methods behind the exploits have not been made public, so it's unclear how exactly they work and if there are other Galaxy devices affected by these issues. Usually, new exploits are detailed in official security changelogs once they get patched. We might hear more about these vulnerabilities in the coming months.
Mihai is a blogger and column writer at SamMobile. His first Samsung phone was an A800 which took a lot of beating, and a part of him still misses the novelty of the clamshell design. In his free time, he enjoys watching shows, documentaries, and stand-up comedy; listening to music, taking walks, and occasionally playing old(er) video games.