At Pwn2Own, researchers exploit fully patched versions of Firefox, Chrome, IE 11, and Safari, while payouts total $557K
Context & Ripple Effects
The 2015 contest put all four major browsers on the board in one event: fully patched builds of Firefox, Chrome, Internet Explorer 11 and Safari fell to researchers, with $557K paid out across the field. It was an early snapshot of a contest that kept growing — by Pwn2Own Toronto 2023 researchers were clearing $1M+ for 58 consumer-product zero-days, including four separate defeats of a patched Galaxy S23.
First-order effects
- Mozilla, Google, Microsoft and Apple each face immediate patch work for their flagship browsers, with exploit details now disclosed through the contest's coordinated process rather than sold privately.
- Participating researchers collect cash awards directly at the event, making the contest itself a payout venue rather than a demonstration-only exercise.
Second-order effects
- Browser vendors respond by standing up their own year-round bounty programs to compete for the same research talent the contest aggregates, shifting vulnerability disclosure toward paid channels.
- The contest's scope widens beyond browsers into adjacent targets — virtualization and client software like VMware Workstation and Oracle VirtualBox appeared as targets by the 2019 Vancouver editions, alongside Firefox and Safari wins worth $270K and $240K respectively.
Third-order effects
- A durable market structure emerges around zero-day research: contests, vendor bounties and broker payouts set reference prices for exploits, pulling disclosure out of ad hoc channels and into a monetized pipeline that persists across a decade of events — from this 2015 round through Pwn2Own Berlin 2026's $385,750 day-two haul against Windows 11 and Red Hat Enterprise Linux.
The trend: Zero-day discovery is professionalizing from one-off contest stunts into a standing, priced market where vendors, contest operators and researchers compete for the same vulnerabilities.