/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Windows, Ubuntu, macOS, Adobe Reader, and desktop Safari were exploited during the 2020 Pwn2Own hacking contest, which was held virtually

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

The 2020 result extends a pattern the related coverage documents well: at Pwn2Own 2015 researchers broke fully patched Firefox, Chrome, IE 11, and Safari for $557K in payouts, and in 2017 a chained Edge/Windows 10/VMware exploit achieved a full VM escape to the host. Last year's Vancouver edition again fell to Safari, Oracle VirtualBox, and VMware Workstation exploits.

What changed this year is the format and the breadth: the contest ran virtually rather than on-site in Vancouver, and targets spanned every major desktop OS — Windows, Ubuntu, macOS — plus Adobe Reader and desktop Safari. Safari's repeated appearance as a casualty across 2015, 2019, and now 2020 makes it the contest's most consistent browser target.

First-order effects

  • Apple, Microsoft, Canonical, and Adobe each leave the contest holding newly demonstrated exploitable bugs in shipping software, with coordinated disclosure through the Zero Day Initiative putting them on a fixed patching clock.
  • Desktop Safari's continued success as a target adds to Apple's security track record at this event, following its exploitation in both the 2015 and 2019 editions.

Second-order effects

  • Later the same year, China's Tianfu Cup drew researchers with larger prizes — Qihoo 360's winning team took $744K hacking Windows 10, iOS 14, Chrome, Safari, and Firefox ([[a:959824]]) — giving vulnerability researchers a second, better-paying stage and pressuring Pwn2Own's payout model.
  • VMware's recurring role as an escape vector from 2017 onward keeps hypervisor isolation under scrutiny as a chaining component rather than a hard boundary.

Third-order effects

  • If the two-contest structure holds, vendor security becomes benchmarked on a semiannual public schedule, turning exploit demonstrations into a recurring reputational and patch-cadence pressure point for OS and browser makers.
  • A virtual format removes the travel barrier to entry, which points toward a broader, more geographically distributed researcher pool competing against vendors' fix cycles.

The trend: Exploit contests are consolidating into a global, recurring market — Pwn2Own plus regional rivals like Tianfu Cup — that publicly benchmarks major OS and browser vendors' security twice a year.

Discussion

  • @whatthebit Stefan Constantine on x
    good job, hackers hope you get paid hope you get hired by these companies https://twitter.com/...