/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers earned $1M+ for 58 zero-day exploits targeting consumer products at Pwn2Own Toronto 2023 and hacked a fully patched Samsung Galaxy S23 four times

The Pwn2Own Toronto 2023 hacking competition has ended with security researchers earning $1,038,500 for 58 zero-day exploits …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Pwn2Own’s consumer-device focus was already visible in the 2022 Toronto event’s exploits against Galaxy phones, printers, routers and NAS devices. This edition broadens that pattern into a larger set of demonstrated flaws across consumer products.

The Galaxy S23 results also extend a longer mobile-testing record: Mobile Pwn2Own 2017 produced breaches of major iPhone, Samsung and Huawei devices. The continuing recurrence matters because fully patched flagship devices remain a meaningful test of defensive depth.

First-order effects

  • Samsung and the other affected product vendors must assess the demonstrated zero-days, with the Galaxy S23’s four successful compromises showing that current patch status did not prevent the contest attacks.
  • Researchers receive more than $1 million in rewards for disclosing 58 exploit paths, reinforcing Pwn2Own as a paid channel for finding consumer-product vulnerabilities.

Second-order effects

  • Rival device and connected-product makers face added pressure to test exploit chains—not only known, individually patched bugs—across phones, routers, printers and storage devices.
  • The results strengthen the market role of organized vulnerability research: vendors can use contest disclosures to prioritize remediation, while researchers have a visible alternative to retaining unpublished findings.

Third-order effects

  • If repeated across events, competitive exploit demonstrations will make ecosystem cyber defense a more continuous product requirement, rather than a response reserved for high-profile incidents.
  • The pattern suggests consumer-device security will increasingly be judged by resilience against chained zero-days in fully updated products; the corpus does not establish how quickly any individual vendor will close the gaps.

The trend: Pwn2Own results are part of a broader shift toward recurring, incentivized adversarial testing of consumer technology ecosystems.

Discussion

  • @thezdi @thezdi on x
    Success! STAR Labs SG was able to exploit a permissive list of allowed inputs against the Samsung Galaxy S23. They earn $25,000 and 5 Master of Pwn points. #Pwn2Own [image]
  • @0xcharlie Charlie Miller on x
    Interesting data from this week's Pwn2Own. 1) No attempts against Google Pixel or iPhone even though they are worth 4-5x other targets. 2). 15 straight years of hacking Apple products at Pwn2Own ended last year and continues this year. Apple is secure now? 1/n
  • @0xcharlie Charlie Miller on x
    3) The only interesting (to me) device getting targeted is Samsung Galaxy. 4) Why is pwn2own targeting smart speakers and printers? That's so easy even I could do it and I'm old. 5) When did pwn2own have rules written by lawyers? Used to be a tweet, a blog if you were lucky.
  • @thezdi @thezdi on x
    That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January. [image]
  • @pentestltd @pentestltd on x
    #Pwn2Own Toronto released a nice little short of our Samsung Galaxy S23 exploit. Why does hacking always look cooler in film/video? 🤷‍♂️ @thezdi [video]
  • @claroty @claroty on x
    Today at #Pwn2Own Toronto, Team82 chained 4 exploits to remotely attack a TP-Link Omada router, then pivot to the local network to access a Synology BC500 camera. All technical details were disclosed to the vendors. Team82 was awarded $40,000 USD in prize money for its efforts. […
  • r/InfoSecNews r on reddit
    Hackers earn over $1 million for 58 zero-days at Pwn2Own Toronto