Researchers hacked Apple's Safari, Oracle VirtualBox, and VMware Workstation in Pwn2Own Vancouver 2019 contest, earning $240K in cash awards
SUBSCRIBE — The first day of Pwn2Own Vancouver 2019 is in the books and already, we've seen some great research.
Context & Ripple Effects
Day one of Pwn2Own Vancouver 2019 set a fast pace: Safari, Oracle VirtualBox, and VMware Workstation all fell to fully patched exploits worth $240K, before researchers returned two days later to take down Firefox, a VMware Workstation client, and Microsoft Edge for another $270K. VMware Workstation is a repeat target — the same virtualization layer was used in a 2017 VM-escape chain against Microsoft Edge and Windows 10.
The prize pool trajectory frames why this matters: Pwn2Own paid out $557K across an entire contest in 2015, while by Pwn2Own Toronto 2023 a single event cleared $1M+ for 58 zero-days against consumer products.
First-order effects
- Apple, Oracle, and VMware each receive working exploit code for fully patched products on day one, forcing immediate patch development for Safari, VirtualBox, and Workstation respectively.
- The winning researchers collect $240K in cash awards, converting undisclosed vulnerabilities into monetized disclosures within the contest's rules.
Second-order effects
- Vendors whose products survived day one — Mozilla's Firefox and Microsoft's Edge among them — face heightened exposure as researchers reinvest winnings into day-two targets, which duly fell for another $270K.
- Recurring success against VMware Workstation pressures virtualization vendors to treat guest-to-host escape chains as a first-class threat model rather than a theoretical one.
Third-order effects
- If payout growth holds — from $557K per full contest in 2015 toward seven-figure single events like Toronto 2023 — coordinated bounty contests keep professionalizing zero-day research, pulling talent away from purely black-market sales.
- The pattern also pushes platform vendors toward faster patch cadences and layered mitigations, since contest results demonstrate that any single vendor's 'fully patched' status is a temporary condition.
The trend: Exploit-contest prize pools are scaling from hundreds of thousands per event toward millions, turning zero-day demonstration into a structured, recurring market between researchers and major software vendors.