/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers hacked Mozilla's Firefox, a VMware Workstation client, and Microsoft Edge on the second day of Pwn2Own Vancouver 2019, earning $270K in cash awards

Dustin Childs / Zero Day Initiative :

Zero Day Initiative Dustin Childs

Context & Ripple Effects

Day two extends what was already a lucrative opening at Vancouver: on day one, researchers took $240K by hitting Apple's Safari, Oracle VirtualBox, and VMware Workstation. The second day keeps the pressure on the same stack — Firefox, a VMware Workstation client, and Microsoft Edge fall for another $270K.

The targets rhyme with prior years. Edge and VMware Workstation were the combination behind the 2017 guest-to-host virtual machine escape in Windows 10, and Firefox has been a recurring Pwn2Own victim since the 2015 contest where all four major browsers fell for $557K total.

First-order effects

  • Mozilla, Microsoft, and VMware each receive fresh zero-day vulnerability reports against fully patched products, starting their disclosure-and-patch clocks under ZDI's coordinated process.
  • The researchers who demonstrated the Firefox, VMware Workstation client, and Edge exploits split $270K in cash awards on top of the $240K paid out the previous day.

Second-order effects

  • VMware Workstation being exploited on both contest days confirms it as a prime target alongside browsers, pushing virtualization vendors to harden guest-to-host attack surfaces the way browser makers hardened sandboxes after 2015.
  • Microsoft faces repeated Edge compromises across contests — including the 2017 chain that escaped the VM to compromise the host — reinforcing the case for its sandbox and patch-cadence investments.

Third-order effects

  • With payouts climbing from $557K in 2015 toward the $800K-plus awarded on a single day by Pwn2Own Vancouver 2022, bug-bounty contests are consolidating into a structured market where vendors effectively outsource penetration testing of browsers and hypervisors.
  • If hypervisor escapes keep landing next to browser exploits, the industry's trust model shifts: isolation layers once assumed to contain browser compromise become themselves audited, patched attack surface.

The trend: Pwn2Own is scaling from a stunt contest into a recurring zero-day marketplace, with browsers and virtualization platforms as its most reliably breached categories.