At Pwn2Own Vancouver 2022, several bugs were exploited in Microsoft, Ubuntu, and Tesla products; first day saw $800K+ awarded for exploiting 16 zero-day bugs
Several bugs in Microsoft, Ubuntu and Tesla products were found and exploited during the three-day Pwn2Own hacking conference in Vancouver this week.
Context & Ripple Effects
Pwn2Own had already demonstrated that chained flaws could turn browser, operating-system, and virtualization weaknesses into a host compromise in a 2017 virtual-machine escape demonstration. The 2022 results extend that public stress test across Microsoft, Ubuntu, and Tesla products.
The same contest later recorded 19 zero-days across Windows 11, Tesla, Ubuntu, and other products in 2024, while the 2026 Berlin event added successful exploits against AI products. That sequence makes the 2022 disclosures an early point in a continuing expansion of contest-tested attack surfaces.
First-order effects
- Microsoft, Ubuntu, and Tesla have publicly demonstrated vulnerabilities to assess, with 16 zero-day exploits earning more than $800,000 on the event’s first day.
Second-order effects
- Pwn2Own’s later return to Windows, Tesla, and Ubuntu shows that these vendors face recurring public comparisons of product hardening rather than a one-off test cycle.
Third-order effects
- As the contest broadens from operating systems, browsers, and vehicles to AI products, public exploit competitions are becoming a cross-category benchmark for defensive maturity and vulnerability research incentives.
The trend: Pwn2Own is evolving from a test of conventional endpoint and vehicle security into a recurring disclosure venue spanning the software and AI products that concentrate user trust and code-execution risk.