Safari, Virtualbox, VMware Get Hacked During First Day of Pwn2Own 2019

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
During the first day of Pwn2Own Vancouver 2019, contestants were able to successfully hack into the Apple Safari web browser, Oracle's VirtualBox, and VMware Workstation, earning a total of $240,000 in cash awards.

The Fluoroacetate team targeted all three apps during the first day of Pwn2Own, successfully exploiting all of them and making $160,00 in the process.
First to go down was Apple's Safari which they managed to hack using a bug in JIT with a heap overflow to escape the sandbox according to the Pwn2Own Vancouver 2019 results.

Next, they used "an integer underflow and a race condition to escape the virtual machine and pop calc on the underlying OS" when targeting Oracle VirtualBox, in the contest's virtualization category.

The last program they exploited was VMware Workstation, the one who also brought them a $70,000 award after "leveraging a race condition leading to an out-of-bounds write in the VMware client to execute their code on the host OS."
 

Dave Russo

Level 22
Verified
Top Poster
Well-known
May 26, 2014
1,130
Ok ,no one is safe, paranoia seems to be the result of reading this report,never the less ,there was some big cash involved,so I guess,there is a effort of these test, to improve there security,when loopholes are found??? Anyone know Thanks
 
  • Like
Reactions: bribon77

bribon77

Level 35
Verified
Top Poster
Well-known
Jul 6, 2017
2,392
Ok ,no one is safe, paranoia seems to be the result of reading this report,never the less ,there was some big cash involved,so I guess,there is a effort of these test, to improve there security,when loopholes are found??? Anyone know Thanks
Well said, now the developers of these programs take action as a result of this test and improve their programs.:giggle:
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
With these reports, paranoia would be the worst emotion to have. Least the bug bounty programs work, these guys probably get a decent living.

~LDogg
 
  • Like
Reactions: Dave Russo

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top