Be quick, CYBER MONDAY deals! Galaxy Watch 7, Samsung TV, Galaxy Buds 3 Pro and Galaxy S24 Ultra.

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

News For You
News For You
Notifications

Galaxy S23 and rival Xiaomi 13 Pro get hacked live

Phone
By 

Last updated: October 25th, 2023 at 11:37 UTC+02:00

The Galaxy S23 may be one of the most secure Android phones, but it is not impermeable. No smartphone is, regardless of who manufactures it. The Zero Day Initiative's ongoing Pwn2Own event in Toronto highlights that consumer electronics are always susceptible to attacks, and smartphones from both Samsung and Xiaomi were the focus of some newly discovered zero-days.

A zero-day is a vulnerability in a computer system that was previously unknown to its developers or anyone capable of mitigating it (via Wikipedia). Through its Pwn2Own event, the Zero Day Initiative encourages security researchers to report zero-day vulnerabilities privately to vendors. Cash rewards are at stake.

On the first day of the ongoing Pwn2Own 2023 Toronto event, researchers were able to exploit two zero-days affecting the Galaxy S23 and two zero-days on the Xiaomi 13 Pro. Once again, these exploits were previously unknown to Samsung, Google (and Xiaomi), or anyone able to patch them.

Story continues after the video

$75,000 awarded for discovering two Galaxy S23 zero-days

According to the Zero Day Initiative blog, Star Labs SG was able to exploit a permissive list of allowed input against the Galaxy S23. For discovering and demonstrating this zero-day, they earned $25,000 and 5 Master of Pwn points.

The bigger prize of $50,000 and 5 Master of Pwn points went to Pentest Limited for executing an Improper Input Validation on the Galaxy S23.

These newly-discovered vulnerabilities will likely be addressed with future security patches, and the exploit methods kept in secrecy untile then.

Security researchers have also found zero-days in the Xiaomi 13 Pro. Team Viettel earned $40,000 for executing a single-bug attack against the Xiaomi 13 Pro, and NCC Group earned $20,000 by demonstrating a zero-day on the same device.

All of this happened on the first day of the Pwn2Own 2023 Toronto event. There is a high probability that even more zero-days will be demonstrated before the event ends on October 27. We'll keep you posted.

Phone Galaxy S23Galaxy S23 PlusGalaxy S23 UltraXiaomi Buy now!
Scroll for more related content
News For You

You might also like

Screenshots of more One UI 7.0 apps leak, one app even available for download!

Screenshots of more One UI 7.0 apps leak, one app even available for download!

More screenshots of Samsung apps from One UI 7.0 have leaked online, courtesy of Gerwin van Giessen on X/Twitter. One of those apps—Samsung Reminder—is even available for download and works fine on existing devices like the Galaxy S24 Ultra and the Galaxy Z Fold 6. One UI 7.0 will bring updated user interface to various […]

  • By Abhijeet Mishra
  • 5 days ago
Quickly create GIFs using the camera on your Galaxy smartphone

Quickly create GIFs using the camera on your Galaxy smartphone

Do you like sharing GIFs on social media and messaging apps? Do you also like creating your own GIFs instead of just sharing what’s already available in the apps you use or the keyboard you type on? Galaxy smartphones offer several methods of creating GIF files. One of those involves swiping and holding the shutter […]

  • By Abhijeet Mishra
  • 5 days ago
Checking for updates on your Galaxy phone and getting nothing? You’re not alone

Checking for updates on your Galaxy phone and getting nothing? You’re not alone

Have you been wondering why your Galaxy smartphone has not notified you of a new update this month and why there's nothing available even when you check for updates manually? Well, you're not alone. Samsung releases monthly security updates for several Galaxy smartphones, and it rolled out the November 2024 update for some devices at […]

  • By Abhijeet Mishra
  • 6 days ago
Samsung’s final One UI 7.0 release roadmap may have been uncovered

Samsung’s final One UI 7.0 release roadmap may have been uncovered

There's been some back and forth about Samsung's release plans for One UI 7.0, but we may have finally pinpointed the company's tentative release roadmap, starting with the beta program. Samsung's One UI 7.0 release program will reportedly look something like this: Galaxy S24 will get the first One UI 7.0 public beta build in […]

  • By Mihai Matei
  • 2 weeks ago
Galaxy S23 November 2024 software update may finally go global

Galaxy S23 November 2024 software update may finally go global

The latest security update for the Galaxy S23 series may finally roll out globally. At the beginning of the month, Samsung released the November 2024 software update for the Galaxy S23 series in the USA, but the update didn't go live in any other market for nearly three weeks. That is no longer the case. […]

  • By Abhijeet Mishra
  • 2 weeks ago
Galaxy S23 Android 15 test firmware go live on Samsung servers

Galaxy S23 Android 15 test firmware go live on Samsung servers

Samsung may finally have started development on the Android 15 firmware for the Galaxy S23 series (via Tarun Vats). The Galaxy S23 series is expected to be among the first batch of devices that get the One UI 7.0 beta program later this year, but for some reason Android 15 testing for the 2023 flagship […]

  • By Abhijeet Mishra
  • 2 weeks ago