The Google Pixel was hacked by a group of Chinese hackers, while Apple Safari and, classically, Adobe Flash fell beside it in a hacking competition, PwnFest, that took place in Seoul on Friday.
The latest offering device from Mountain View was breached by a white-hat from the Chinese company Qihoo 360, who used an unknown vulnerability to achieve remote code execution, winning $120,000 as a cash prize.
The exploit opens the Google Play store before Chrome runs and displays a webpage that says: “Pwned By 360 Alpha Team”.
Google is now trying to develop a patch that fixes the vulnerability.
We should note that this is the second time in two weeks that the security of the Pixel has been breached. The first time (the zero-day is still unpatched) the exploit was developed by the rival team of Qihoo 360, Keen of Tencent, and was made public at the Mobile Pwn2Own event in Japan.
After the hack on Google Pixel, others followed:
Apple's Safari now, fully updated on MacOS Sierra, didn't seem very lucky. Also the Chinese hackers of Pangu, a group known for releasing tools for iOS jailbreak together with hacker JH, breached Cupertino's browser using a zero day that gave them root access. The hack took 20 seconds and they earned $80,000.
The Qihoo 360 team also breached Adobe Flash (with a finger), using a zero-day that had been discovered ten years ago and a Win32k vulnerability. They earned another $120,000, and it took four seconds.
Another notable hack at PwnFest was on Microsoft Edge as well as a zero-day exploit (the first) against VMWare Workstation that was presented on Thursday.
The Qihoo 360 hackers left with $520,000 in prize money from the event.
