/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

At Pwn2Own, researchers exploit fully patched versions of Firefox, Chrome, IE 11, and Safari, while payouts total $557K

HP Awards $240K for Firefox, IE, Chrome and Safari Exploits  —  On March 19, the second day of the Hewlett-Packard Zero Day Initiative (ZDI) sponsored Pwn2Own hacking challenge …

eWeek Sean Michael Kerner

Context & Ripple Effects

The 2015 edition of HP's Zero Day Initiative contest ended with all four major browsers — Firefox, Chrome, Internet Explorer 11, and Safari — falling to researchers despite being fully patched, with $557K disbursed overall and $240K of it for the browser exploits alone. It established the template the contest still runs on today: vendors hand researchers fully updated software, ZDI buys the break, and the payout becomes the public price signal for a zero-day.

That signal has compounded since. The same event structure later produced a $1M+ haul for 58 zero-days at Toronto 2023, expanded past browsers into hypervisors like VMware Workstation and Oracle VirtualBox by 2019, and by Pwn2Own Berlin 2026 was paying out $385K in a single day — making this 2015 round the early baseline for what browser bugs fetch.

First-order effects

  • Mozilla, Google, Apple, and Microsoft each walk away holding details of a working exploit against their shipping browser code, putting emergency patches on every vendor's immediate agenda ahead of coordinated disclosure through ZDI.

Second-order effects

  • Vendors' own private bounty programs now have to compete with a public contest that pays cash on stage for the same class of bugs, pushing retention terms upward for exactly the researchers who can chain full-browser compromises.

Third-order effects

  • If the trajectory holds — from $557K across a whole 2015 event to seven-figure totals and per-day payouts approaching half a million dollars — the contest cements itself as the reference market where zero-day prices for consumer software are publicly set.

The trend: Consumer software security is consolidating around an annual paid-exploit circuit, with ZDI's escalating Pwn2Own payouts functioning as the visible price index for zero-day vulnerabilities.