Home » Technology » Pwn2own Premiere in Berlin: Windows 11 and Firefox cracked

Pwn2own Premiere in Berlin: Windows 11 and Firefox cracked

The Berlin premiere of the Hacking competition PWN2OWN ended with a rather impressive record: Prize money of over one million dollars (967,000 euros) was distributed and 28 newly discovered security gaps were reported to the manufacturers.

Top platforms in the security check

The international security experts demonstrated their skills on systems such as Windows 11, Linux and Firefox and that is extremely successful. Already on the second day, the participants had disclosed 20 Zero-Day weak points. In addition to classic destinations such as operating systems and browsers, virtualization solutions and network components were also successfully attacked.

Premiere for AI security tests

The Zero Day Initiative (ZDI) operated by Trend Micro introduced a special AI category for the first time. In contrast to simple prompt injections, the participants had to achieve complete code version on AI frameworks. The seven discovered AI weak spots underline the growing importance of this technology for cyber security.

Security through cooperation

As always, the weaknesses discovered were passed on to the manufacturers, which typically have 90 days to develop updates. This procedure, first introduced in 2007 on Cansecwest, has established itself as an effective mechanism to strengthen the digital safety landscape. The Star Labs SG team won the coveted “Master of Pwn” title with $ 320,000 (287,000 euros) and 35 points.

The permanent topic Firefox and Manfred Paul was also represented again. This time he showed how the browser could be compromised by an integer-overflow error and received $ 50,000 ($ 45,000). Successful Windows 11 hacks were:

  • Chen Le Qi from Starlabs SG combined a UAF and an integer overflow to get to the system level under Windows 11. It receives $ 30,000 and 3 Master of PWN points.
  • Marcin Wiązowski’s privilege extension was confirmed under Windows 11. He used an out-of-bound write to get to the system level. His work brings him $ 30,000 and 3 Master of PWN points.
  • Hyeonjin Choi from Out of Bounds receives $ 15,000 for victory in the third round and 3 Master of PWN points by successfully using a Type Confusion Bug to escalate privileges in Windows 11.