Researchers hacked Mozilla's Firefox, a VMware Workstation client, and Microsoft Edge on the second day of Pwn2Own Vancouver 2019, earning $270K in cash awards
Dustin Childs / Zero Day Initiative :
Context & Ripple Effects
Day two extends what was already a lucrative opening at Vancouver: on day one, researchers took $240K by hitting Apple's Safari, Oracle VirtualBox, and VMware Workstation. The second day keeps the pressure on the same stack — Firefox, a VMware Workstation client, and Microsoft Edge fall for another $270K.
The targets rhyme with prior years. Edge and VMware Workstation were the combination behind the 2017 guest-to-host virtual machine escape in Windows 10, and Firefox has been a recurring Pwn2Own victim since the 2015 contest where all four major browsers fell for $557K total.
First-order effects
- Mozilla, Microsoft, and VMware each receive fresh zero-day vulnerability reports against fully patched products, starting their disclosure-and-patch clocks under ZDI's coordinated process.
- The researchers who demonstrated the Firefox, VMware Workstation client, and Edge exploits split $270K in cash awards on top of the $240K paid out the previous day.
Second-order effects
- VMware Workstation being exploited on both contest days confirms it as a prime target alongside browsers, pushing virtualization vendors to harden guest-to-host attack surfaces the way browser makers hardened sandboxes after 2015.
- Microsoft faces repeated Edge compromises across contests — including the 2017 chain that escaped the VM to compromise the host — reinforcing the case for its sandbox and patch-cadence investments.
Third-order effects
- With payouts climbing from $557K in 2015 toward the $800K-plus awarded on a single day by Pwn2Own Vancouver 2022, bug-bounty contests are consolidating into a structured market where vendors effectively outsource penetration testing of browsers and hypervisors.
- If hypervisor escapes keep landing next to browser exploits, the industry's trust model shifts: isolation layers once assumed to contain browser compromise become themselves audited, patched attack surface.
The trend: Pwn2Own is scaling from a stunt contest into a recurring zero-day marketplace, with browsers and virtualization platforms as its most reliably breached categories.