Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

$1 Million Offered for WhatsApp Exploit at Pwn2Own Ireland 2025

Meta is sponsoring ZDI’s Pwn2Own hacking competition, where participants can earn big prizes for smartphone, WhatsApp and wearable device exploits.

Hackers

Trend Micro’s Zero Day Initiative (ZDI) has announced the targets and prizes for the upcoming Pwn2Own hacking event, set to take place in Cork, Ireland, on October 21-24.

Meta is a sponsor of Pwn2Own Ireland 2025 and up to $1 million is being offered for a WhatsApp exploit that enables remote code execution with no user interaction.

In addition, a one-click WhatsApp remote code execution exploit can earn participants up to $500,000, while a zero-click account takeover exploit can be worth up to $150,000. 

Remote zero-click exploits that enable access to the microphone or video feed, or access to sensitive user data are worth up to $130,000. An exploit that enables access to user data is worth the same amount even if it requires one click.

At last year’s Pwn2Own Ireland hacking competition, a zero-click WhatsApp exploit was worth up to $300,000, but no one demonstrated such exploits. Meta and ZDI are significantly increasing the reward this year.

Pwn2Own participants can this year earn up to $300,000 for remote exploits targeting Pixel 9 and iPhone 16 smartphones. A remote Samsung Galaxy hack is worth $50,000. USB has also been introduced as an attack vector this year. 

Advertisement. Scroll to continue reading.

Significant prizes are also being offered for exploits targeting Meta wearables, including Meta Ray-Ban smart glasses and the Meta Quest VR headset. Prizes range between $30,000 for jailbreaks and $150,000 for zero-click remote code execution.

Researchers can earn up to $100,000 in the SOHO Smashup category, where they need to compromise a networking device and then move laterally on the network to hack a smart speaker, NAS device, or camera.

Other categories include NAS, smart home devices (both categories with rewards of up to $50,000), surveillance systems (up to $30,000), and printers (up to $20,000). 

More than $1 million was paid out at Pwn2Own Ireland 2024 for exploits targeting smartphones, cameras, printers, NAS devices and smart speakers.

Related: Hackers Earn $886,000 at Pwn2Own Automotive 2025 for Charger, OS, Infotainment Exploits

Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Related: WhatsApp Vulnerability Could Facilitate Remote Code Execution

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.