Windows, Ubuntu, macOS, Adobe Reader, and desktop Safari were exploited during the 2020 Pwn2Own hacking contest, which was held virtually
Context & Ripple Effects
The 2020 result extends a pattern the related coverage documents well: at Pwn2Own 2015 researchers broke fully patched Firefox, Chrome, IE 11, and Safari for $557K in payouts, and in 2017 a chained Edge/Windows 10/VMware exploit achieved a full VM escape to the host. Last year's Vancouver edition again fell to Safari, Oracle VirtualBox, and VMware Workstation exploits.
What changed this year is the format and the breadth: the contest ran virtually rather than on-site in Vancouver, and targets spanned every major desktop OS — Windows, Ubuntu, macOS — plus Adobe Reader and desktop Safari. Safari's repeated appearance as a casualty across 2015, 2019, and now 2020 makes it the contest's most consistent browser target.
First-order effects
- Apple, Microsoft, Canonical, and Adobe each leave the contest holding newly demonstrated exploitable bugs in shipping software, with coordinated disclosure through the Zero Day Initiative putting them on a fixed patching clock.
- Desktop Safari's continued success as a target adds to Apple's security track record at this event, following its exploitation in both the 2015 and 2019 editions.
Second-order effects
- Later the same year, China's Tianfu Cup drew researchers with larger prizes — Qihoo 360's winning team took $744K hacking Windows 10, iOS 14, Chrome, Safari, and Firefox ([[a:959824]]) — giving vulnerability researchers a second, better-paying stage and pressuring Pwn2Own's payout model.
- VMware's recurring role as an escape vector from 2017 onward keeps hypervisor isolation under scrutiny as a chaining component rather than a hard boundary.
Third-order effects
- If the two-contest structure holds, vendor security becomes benchmarked on a semiannual public schedule, turning exploit demonstrations into a recurring reputational and patch-cadence pressure point for OS and browser makers.
- A virtual format removes the travel barrier to entry, which points toward a broader, more geographically distributed researcher pool competing against vendors' fix cycles.
The trend: Exploit contests are consolidating into a global, recurring market — Pwn2Own plus regional rivals like Tianfu Cup — that publicly benchmarks major OS and browser vendors' security twice a year.