Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not what Zerodium says[1]. They claim, and are backing it up with millions of dollars, that current Android exploits are more valuable than current iOS, because of a large supply of iOS issues.

[1]: https://www.wired.com/story/android-zero-day-more-than-ios-z...



In the article they discuss that it’s lkelly a publicity stunt.


0dium's actual prices are likely a publicity stunt, but it says quite clearly, citing several different, independent sources, that attacks against a fully patched Android system are now worth more than the equivalent attack against a fully patched iOS machine. That is in part because Android has hardened up recently, Safari and iMessage in particular are highly vulnerable, and also because there was more money recently in iOS and so there was more attention on it.

To a certain extent, of course, attacks against Android outside of flagship Samsung and Google phones are much cheaper- look at any patchset and attack, and given that 30+% of the Android user base is on Nougat/Oreo and 10% is on Kitkat or earlier as a whole they are far more exposed.


No, it says they might be trying to influence market prices. Another researcher quoted in the article confirms that the market price for an exploit of a high end Android device is 30% more than an equivalent iOS exploit and gives Safari's poor security as the reason. Despite Safari having such a large attack surface, iOS cannot update it without a reboot, which only exacerbates the problem.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: