/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

On Pwn2Own Vancouver 2024 Day 1, contestants earned $732,500 and a Tesla Model 3 for demoing 19 zero-days in Windows 11, Tesla cars, Ubuntu, and other products

On the first day of Pwn2Own Vancouver 2024, contestants demoed Windows 11, Tesla, and Ubuntu Linux zero-day vulnerabilities …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Pwn2Own has repeatedly surfaced exploitable flaws across the same broad software and automotive stack: the 2022 Vancouver contest exposed bugs in Microsoft, Ubuntu and Tesla products. This day-one result shows that cross-platform attack research remains productive even as vendors harden widely used systems.

Automotive targets had already become a dedicated focus, with the first car-focused Pwn2Own event producing 49 automotive zero-days. Tesla's presence alongside Windows 11 and Ubuntu reinforces how vehicle security is being tested within the wider consumer-device ecosystem.

First-order effects

  • Tesla, Microsoft, Ubuntu and other affected vendors must assess the 19 demonstrated zero-days and prioritize remediation for the attack paths validated during the contest.
  • Researchers received $732,500 and a Tesla Model 3, directly rewarding working exploit research across desktop, Linux and automotive targets.

Second-order effects

  • The results increase pressure on vendors to treat exploit-chain resistance—not just individual bug counts—as a competitive security priority, since contest demonstrations validate practical impact.
  • Automotive security teams face closer comparison with traditional endpoint and operating-system vendors as cars continue to appear in the same public vulnerability-research venues.

Third-order effects

  • If contests continue to yield multi-platform zero-days, security assurance will increasingly be judged by how quickly vendors absorb external research and reduce exploitable chains across product layers.
  • The pattern points to convergence between automotive and general-purpose computing security: connected vehicles are becoming a sustained target class for the same specialist research market.

The trend: Pwn2Own is becoming a clearer measure of the expanding market for defensive research spanning operating systems, consumer devices and connected vehicles.

Discussion

  • @thezdi @thezdi on x
    Confirmed! Our final attempt of the day had Manfred Paul (@_manfp) execute a double-tap on both #Chrome and #Edge browsers with the rare CWE-1284 Improper Validation of Specified Quantity in Input. He earns $42,500 and 15 Master of Pwn points. #Pwn2Own [image]
  • @thezdi @thezdi on x
    Confirmed! @le_douds and @Ga1ois from Palo Alto used an OOB Read plus a novel technique for defeating V8 hardening to get arbitrary code execution in the renderer. The were aboe to exploit #Chrome and #Edge with the same bugs, earning $42,500 and 9 Master of Pwn points. #Pwn2Own …
  • @hosselot Hossein Lotfi on x
    ... and all major browsers have fallen in #Pwn2Own Vancouver 2024 (all in the first try of exploit): 1) Google Chrome/Microsoft Edge renderer: 4 attempts, 4 successes. 2) Apple Safari renderer: 1 attempt, 1 success. 3) Mozilla Firefox(+ sandbox escape): 1 attempt, 1 success.
  • @thezdi @thezdi on x
    That's a wrap! #Pwn2Own Vancouver is complete. Overall, we awarded $1,132,500 for 29 unique 0-days. Congrats to @_manfp for winning Master of Pwn with $202,500 and 25 points. Here's the final top 10 list: [image]
  • @ale_sp_brazil Alexandre Borges on x
    Manfred Paul @_manfp, who is talented, discreet and hardworking, has exploited #Chrome, #Edge, #Safari, and #Firefox in two days at #Pwn2Own @thezdi , and only published a simple tweet without any hype about it. This reminds me Jung Hoon Lee (@lokihardt), who also broke four... […