Sunday, August 3, 2025
Google search engine
HomeTechnologyCyber SecurityPwn2Own hacking contest pays $1 million for WhatsApp exploit

Pwn2Own hacking contest pays $1 million for WhatsApp exploit


The Zero Day Initiative is providing a $1 million reward to safety researchers who will display a zero-click WhatsApp exploit at its upcoming Pwn2Own Eire 2025 hacking contest.

The file bounty targets zero-click safety flaws that permit code execution with out person interplay on the messaging platform utilized by greater than three billion folks worldwide.

Meta, alongside Synology and QNAP, is co-sponsoring the Pwn2Own Eire 2025 competitors, which can happen from October 21 to October 24 in Cork, Eire.

“As you might need guessed from the title, we’re excited to announce that Meta is co-sponsoring this 12 months’s occasion, and they’re hoping to see some nice WhatsApp exploits. They’re so excited for it, we’re placing up $1,000,000 for a 0-click WhatsApp bug that results in code execution,” the Zero Day Initiative introduced Thursday.

“We additionally can have lesser money awards for different WhatsApp exploits, so remember to take a look at the Messaging part for full particulars. We launched this class final 12 months, however nobody tried it. Maybe a quantity with two commas will present the wanted motivation.”

WhatsApp Pwn2Own awardsWhatsApp Pwn2Own awards (ZDI)

​The competition options eight classes concentrating on cell phones, messaging apps, house networking gear, good house gadgets, printers, community storage techniques, surveillance gear, and wearable expertise, together with Meta’s Ray-Ban Good Glasses and Quest 3/3S headsets, in addition to Samsung Galaxy S25, Google Pixel 9, and Apple iPhone 16 flagship smartphones.

The ZDI has additionally expanded the assault vectors for the cellular class to incorporate USB port exploitation for cellular gadgets, requiring contestants to compromise locked telephones by means of bodily connections. Conventional wi-fi protocols, equivalent to Wi-Fi, Bluetooth, and near-field communication, stay legitimate assault strategies.

Registration closes on October 16 at 5 p.m. Irish Commonplace Time, with the competition order decided by a random drawing. The Zero Day Initiative operates the occasion to establish vulnerabilities earlier than malicious actors can exploit them, coordinating accountable disclosure with affected distributors.

After the failings are exploited throughout Pwn2Own occasions, distributors have 90 days to launch safety updates earlier than Pattern Micro’s Zero Day Initiative publicly discloses them.

Final 12 months’s Pwn2Own Eire occasion awarded $1,078,750 for over 70 distinctive zero-day vulnerabilities, with Viettel Cyber Safety accumulating $205,000 for flaws demonstrated in QNAP NAS, Sonos audio system, and Lexmark printers.


Picus Red Report 2025

Malware concentrating on password shops surged 3X as attackers executed stealthy Good Heist situations, infiltrating and exploiting essential techniques.

Uncover the highest 10 MITRE ATT&CK strategies behind 93% of assaults and find out how to defend towards them.

Learn the Crimson Report 2025



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments