Megalife Phone Hacked?! Yes!

Security/Kashrus at Megalife

At Megalife, we genuinely value experts who try to hack our devices. To that end, we even offer a $500 bounty to anyone who successfully compromises a device and demonstrates a serious vulnerability
(of course, subject to our TOS).

Our philosophy is simple: in this industry, you can never be too careful. We’d much rather uncover loopholes ourselves than leave them for bad actors to find.


Putting Our Security to the Test

Recently, we enlisted the services of @ars18 to search for a meaningful exploit. We hired him fully aware of his capability, persistence, and uncanny ability to fit more than 24 hours into a single day.

He was far from the first expert we engaged, but until now, none of our hires had uncovered anything truly serious.

After extensive effort, and after exhausting both well-known and lesser-known techniques, he succeeded in doing something noteworthy: installing an APK.

While we won’t be sharing details of how this was accomplished, we can confidently say it was a revolutionary approach, and absolutely deserving of a :star::star::star::star::star: review.


Transparency Over Silence

Some might suggest quietly fixing such an issue and keeping it under wraps. We disagree.

We genuinely enjoyed this challenge and are happy to share it publicly. Rest assured: the vulnerability was patched within minutes across all devices, so there’s no need to start pressuring @ars18 for details :wink:


Kudos to @ars18 and onward to even stronger Kashrus.

Thanks! It was fun :slight_smile:

@DonBot you see the difference!!!
BH!

Sorry for the oily keyboard, I was eating deli roll. I promise I’ll clean it soon.

So if the exploit was anyways patched, then can he tell me what he did?

Not because I’m trying to bypass any devices, I don’t even know anyone who own’s a Megalife, I’m just curious.

Well Fig would have said…

Is it the something that can be done on other devices also?

Dunno what you are referring to, but this is something new.

Depending on device, but a very strong chance yes.

Also, it’s a new train of thought to break through these kosher devices, and in case I missed anything… They don’t want it to be known.

I’m not done yet :slight_smile:

Though I will say I think this is the farthest I can go, but I am staying on my firmware version just to make sure. That’s just for fun, it’s already patched in the update.

@Megalife , really appreciate your presence on the forum. It is quite amazing to see the impact it has when companies like yours do this kind of outreach to the community.

No. It’s qualcomm :slight_smile:

And even if you get into edl… You’re not gonna be able to do anything.

This phone has some of the most advanced security around.

So what did you did? Something like package name workaround?

Nah, have more faith in Megalife.

It’s not going to be shared.

Our pleasure :blush:

No Offense

So did he get the 500?

I did.

Even gave me an extra dollar.

@Megalife would you send me a phone ?
Would love to give this a shot

Nice try :grinning_face:.