"The impressive thing about Guang's exploit is that it was one shot; most people these days have to exploit several vulnerabilities to get privileged access and load software without interaction," PacSec organiser Dragos Ruiu told Vulture South. "As soon as the phone accessed the website the JavaScript v8 vulnerability in Chrome was used to install an arbitrary application (in this case a BMX Bike game) without any user interaction to demonstrate complete control of the phone." Unfortunately, real-world applications would be far less benign. Google has already been alerted to the bug and is expected to pay out a sizeable bounty for the heads up.

[Image Credit: Bloomberg via Getty Images]