At Pwn2Own, researchers exploit fully patched versions of Firefox, Chrome, IE 11, and Safari, while payouts total $557K
HP Awards $240K for Firefox, IE, Chrome and Safari Exploits — On March 19, the second day of the Hewlett-Packard Zero Day Initiative (ZDI) sponsored Pwn2Own hacking challenge …
Context & Ripple Effects
The 2015 edition of HP's Zero Day Initiative contest ended with all four major browsers — Firefox, Chrome, Internet Explorer 11, and Safari — falling to researchers despite being fully patched, with $557K disbursed overall and $240K of it for the browser exploits alone. It established the template the contest still runs on today: vendors hand researchers fully updated software, ZDI buys the break, and the payout becomes the public price signal for a zero-day.
That signal has compounded since. The same event structure later produced a $1M+ haul for 58 zero-days at Toronto 2023, expanded past browsers into hypervisors like VMware Workstation and Oracle VirtualBox by 2019, and by Pwn2Own Berlin 2026 was paying out $385K in a single day — making this 2015 round the early baseline for what browser bugs fetch.
First-order effects
- Mozilla, Google, Apple, and Microsoft each walk away holding details of a working exploit against their shipping browser code, putting emergency patches on every vendor's immediate agenda ahead of coordinated disclosure through ZDI.
Second-order effects
- Vendors' own private bounty programs now have to compete with a public contest that pays cash on stage for the same class of bugs, pushing retention terms upward for exactly the researchers who can chain full-browser compromises.
Third-order effects
- If the trajectory holds — from $557K across a whole 2015 event to seven-figure totals and per-day payouts approaching half a million dollars — the contest cements itself as the reference market where zero-day prices for consumer software are publicly set.
The trend: Consumer software security is consolidating around an annual paid-exploit circuit, with ZDI's escalating Pwn2Own payouts functioning as the visible price index for zero-day vulnerabilities.