During the first day of Pwn2Own Vancouver 2019, contestants were able to successfully hack into the Apple Safari web browser, Oracle's VirtualBox, and VMware Workstation, earning a total of $240,000 in cash awards.
The Fluoroacetate team targeted all three apps during the first day of Pwn2Own, successfully exploiting all of them and making $160,00 in the process.
First to go down was Apple's Safari which they managed to hack using a bug in JIT with a heap overflow to escape the sandbox according to the Pwn2Own Vancouver 2019 results.
Next, they used "an integer underflow and a race condition to escape the virtual machine and pop calc on the underlying OS" when targeting Oracle VirtualBox, in the contest's virtualization category.
The last program they exploited was VMware Workstation, the one who also brought them a $70,000 award after "leveraging a race condition leading to an out-of-bounds write in the VMware client to execute their code on the host OS."