zLabs Advanced Mobile Security Research and Exploitation Team
![zLABS_lightBG](https://www.zimperium.com/wp-content/uploads/2024/10/zLABS_lightBG-300x65.png)
The zLabs Advanced Research and Exploitation team is the world’s most qualified and talented collection of researchers focused 100% exclusively on mobile. With backgrounds at companies ranging from eBay and Samsung to Microsoft and Freescale, zLabs researchers are setting the bar for the industry. zLabs researchers discovered and documented attacks such as Stagefright on Android, zIVA on iOS and provided detailed analysis of the FreeRTOS TCP/IP Stack Vulnerabilities. The team have responsibly disclosed more iOS and Android vulnerabilities than all other major competitors combined.
Zimperium’s zLabs team is a key member of the App Defense Alliance. Leveraging our extensive mobile security research expertise and some of the most renown security researchers in the world, zLabs is working with Google to ensure apps entering the Play Store are free of malicious content. Learn more about it here.
![zLabs_page_google_image_C Zimperium App Defense Alliance Google](https://www.zimperium.com/wp-content/uploads/2019/11/zLabs_page_google_image_C.jpg)
Awards & Recognition
The team's awards, certifications, specialized training and recognition are unparalleled in mobile security. Here is just a subset:
![adobe](https://www.zimperium.com/wp-content/uploads/2019/04/adobe.png)
Adobe Independent Security Researchers
![atnt](https://www.zimperium.com/wp-content/uploads/2019/04/atnt.png)
AT&T Bug Bounty Hall of Fame
![barracuda](https://www.zimperium.com/wp-content/uploads/2019/04/barracuda.png)
Barracuda Networks BugBounty Hall of Fame
![bitdefender](https://www.zimperium.com/wp-content/uploads/2019/04/bitdefender.png)
BitDefender Hall of Fame
![hitb](https://www.zimperium.com/wp-content/uploads/2019/04/hitb.png)
Hack in the Box 2017 Machine Learning Competition, 1st Prize
![ceh](https://www.zimperium.com/wp-content/uploads/2019/04/ceh.png)
Certified Ethical Hacker
![coinbase](https://www.zimperium.com/wp-content/uploads/2019/04/coinbase.png)
CoinBase BugBounty Hall of Fame
![chfi](https://www.zimperium.com/wp-content/uploads/2019/04/chfi.png)
Computer Hacking Forensic Investigator
![cpanel](https://www.zimperium.com/wp-content/uploads/2019/04/cpanel.png)
cPanel Full Disclosure
![ebay](https://www.zimperium.com/wp-content/uploads/2019/04/ebay.png)
eBay Security Researchers
![ecsa](https://www.zimperium.com/wp-content/uploads/2019/04/ecsa.png)
Certified Security Analyst
![edx](https://www.zimperium.com/wp-content/uploads/2019/04/edx.png)
edX Certificate, Distributed Machine Learning with Apache Spark
![ekoparty](https://www.zimperium.com/wp-content/uploads/2019/04/ekoparty.png)
EKOPARTY CTF – 1st PLACE
![envato](https://www.zimperium.com/wp-content/uploads/2019/04/envato.png)
Envato Helpful Hacker
![offensive-security](https://www.zimperium.com/wp-content/uploads/2019/04/offensive-security.jpg)
Friends of Offensive Security
![google](https://www.zimperium.com/wp-content/uploads/2019/04/google.png)
Google Application Security Hall of Fame
![kaneva](https://www.zimperium.com/wp-content/uploads/2019/04/kaneva.png)
Kaneva Whitehat Hall of Fame
![microsoft](https://www.zimperium.com/wp-content/uploads/2019/04/microsoft-300x64.png)
Microsoft Certified IT Professional Enterprise Administrator
![microsoft](https://www.zimperium.com/wp-content/uploads/2019/04/microsoft-300x64.png)
Microsoft Certified IT Professional Server Administrator
![microsoft](https://www.zimperium.com/wp-content/uploads/2019/04/microsoft-300x64.png)
Microsoft Security Acknowledged Researchers
![mit](https://www.zimperium.com/wp-content/uploads/2019/04/mit.png)
MIT: Tackling the Challenges of Big Data, Certificate
![nokia](https://www.zimperium.com/wp-content/uploads/2019/04/nokia-300x50.png)
Nokia Responsible Disclosure Hall of Fame
![olark](https://www.zimperium.com/wp-content/uploads/2019/04/olark.png)
Olark Responsible Disclosure Program Special Thanks
![paypal](https://www.zimperium.com/wp-content/uploads/2019/04/paypal.png)
PayPal Wall of Fame, Top 10 Researchers
![stanford](https://www.zimperium.com/wp-content/uploads/2019/04/stanford.png)
Stanford: Cryptography, Certificate
![stanford](https://www.zimperium.com/wp-content/uploads/2019/04/stanford.png)
Stanford: Machine Learning, Certificate
![twitter Twitter Logo](https://www.zimperium.com/wp-content/uploads/2019/04/twitter.png)
Twitter’s Top Hackers on HackerOne
![zynga](https://www.zimperium.com/wp-content/uploads/2019/04/zynga.png)
Zynga Security Whitehat Hall of Fame
![sans](https://www.zimperium.com/wp-content/uploads/2019/04/sans.jpg)
SANS GIAC Reverse Engineering Malware (GREM)
![gmob](https://www.zimperium.com/wp-content/uploads/2019/04/gmob.png)
GIAC Mobile Device Security Analyst (GMOB)
2024 Global Mobile
Threat Report
![Screenshot 2024-09-24 at 4.56.28 PM](https://www.zimperium.com/wp-content/uploads/2024/09/Screenshot-2024-09-24-at-4.56.28-PM-232x300.jpg)
Awarded CVEs
In the last few years, zLabs has discovered and responsibly disclosed more mobile vulnerabilities than all other major competitors combined. Beginning in 2017, here is the growing list:
CVE | Year | Researcher | Platform | Severity |
---|---|---|---|---|
CVE 2020-9773 | 2020 | Chilik Tamir | iOS | Unassigned |
CVE 2020-992 | 2020 | Nikias Bassen | iOS | Unassigned |
CVE-2020-3831 | 2020 | Chilik Tamir | iOS | Unassigned |
CVE-2019-8545 | 2019 | Adam Donenfeld | iOS | Unassigned |
CVE-2019-8804 | 2019 | Christy Mathew | iOS | Unassigned |
CVE-2019-14041 | 2019 | Tamir Zahavi-Brunner | Qualcomm | Unassigned |
CVE -2019-14040 | 2019 | Tamir Zahavi-Brunner | Qualcomm | Unassigned |
CVE-2018-4282 | 2018 | Adam Donenfeld | iOS | Unassigned |
CVE-2018-9411 | 2018 | Tamir Zahavi-Brunner | Android | Unassigned |
CVE-2018-9539 | 2018 | Tamir Zahavi-Brunner | Android | Unassigned |
CVE-2018-16522 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16525 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16526 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16528 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16523 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16524 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16527 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16599 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16600 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16601 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16602 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16603 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-16598 | 2018 | Ori Karliner | FreeRTOS | Unassigned |
CVE-2018-4109 | 2018 | Adam Donenfeld | iOS | Unassigned |
CVE-2018-4087 | 2018 | Rani Idan | iOS | Unassigned |
CVE-2018-4095 | 2018 | Rani Idan | iOS | Unassigned |
CVE-2017-13253 | 2017 | Tamir Zahavi Brunner | Android | High |
CVE-2017-6999 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6998 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6997 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6996 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6995 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6994 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6989 | 2017 | Adam Donenfeld | iOS | 7.8 |
CVE-2017-6979 | 2017 | Adam Donenfeld | iOS | 7.0 |
CVE-2017-5054 | 2017 | Nicolas Trippar | Android | 8.8 |