/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers hacked Apple's Safari, Oracle VirtualBox, and VMware Workstation in Pwn2Own Vancouver 2019 contest, earning $240K in cash awards

SUBSCRIBE  —  The first day of Pwn2Own Vancouver 2019 is in the books and already, we've seen some great research.

Zero Day Initiative Dustin Childs

Context & Ripple Effects

Day one of Pwn2Own Vancouver 2019 set a fast pace: Safari, Oracle VirtualBox, and VMware Workstation all fell to fully patched exploits worth $240K, before researchers returned two days later to take down Firefox, a VMware Workstation client, and Microsoft Edge for another $270K. VMware Workstation is a repeat target — the same virtualization layer was used in a 2017 VM-escape chain against Microsoft Edge and Windows 10.

The prize pool trajectory frames why this matters: Pwn2Own paid out $557K across an entire contest in 2015, while by Pwn2Own Toronto 2023 a single event cleared $1M+ for 58 zero-days against consumer products.

First-order effects

  • Apple, Oracle, and VMware each receive working exploit code for fully patched products on day one, forcing immediate patch development for Safari, VirtualBox, and Workstation respectively.
  • The winning researchers collect $240K in cash awards, converting undisclosed vulnerabilities into monetized disclosures within the contest's rules.

Second-order effects

  • Vendors whose products survived day one — Mozilla's Firefox and Microsoft's Edge among them — face heightened exposure as researchers reinvest winnings into day-two targets, which duly fell for another $270K.
  • Recurring success against VMware Workstation pressures virtualization vendors to treat guest-to-host escape chains as a first-class threat model rather than a theoretical one.

Third-order effects

  • If payout growth holds — from $557K per full contest in 2015 toward seven-figure single events like Toronto 2023 — coordinated bounty contests keep professionalizing zero-day research, pulling talent away from purely black-market sales.
  • The pattern also pushes platform vendors toward faster patch cadences and layered mitigations, since contest results demonstrate that any single vendor's 'fully patched' status is a temporary condition.

The trend: Exploit-contest prize pools are scaling from hundreds of thousands per event toward millions, turning zero-day demonstration into a structured, recurring market between researchers and major software vendors.