Wonder what Symbian exploits they managed?

The PITA descriptors should have thwarted simple buffer overruns (at least if used properly by the long-suffering coder). Notoriously one licensee hacked a debugger driver to be accessible with low capabilities (it made it more convenient) but I think it was blacklisted. What else - Leaked signing keys from a manufacturer, or a logical flaw in the installer/platform security?

