← Back to context

Comment by nvm0n2

2 years ago

iOS has a reputation for having the best security, but how many times have Android/WhatsApp had these sorts of silent-instant-root exploits via invisible messages? I don't remember it happening. Maybe the strategy of writing lots of stuff in Java is paying off there.

Android has had zero click exploits. For example, Stagefright [1]

And even better, there are plenty of old Android phones out which will be vulnerable to various exploits because of weak OTA update support policies.

[1] https://en.wikipedia.org/wiki/Stagefright_(bug)

  • Sigh…there has never been an 0day Stagefright exploit in the wild. And even if there was it wouldn’t have worked on all Android devices due to the OS differences among OEMs.

    Also, there are plenty of old iPhones that do not receive updates anymore and are just as vulnerable so I’m not sure why you needed to get that in.