H his first day Pwn2Own 2014 started quite impressively, after vulnerabilities were presented for three popular browsers, the Internet Explorer τον Firefox και το Safari της Apple. Η δεύτερη μέρα φαίνεται να είναι επίσης εντυπωσιακή, καθώς οι hackers παρουσίασαν ευπάθειες στον Chrome and classic again in Adobe Flash.
Chrome has been hacked by VUPEN, The team που την προηγούμενη μέρα κέρδισε συνολικά 300.000 δολάρια. Η ομάδα έχει καταφέρει να παραβιάσει την ασφάλεια του web browser της Google με ένα use-after-free which affected WebKit and Blink. Combined with a sandbox bypass they discovered, they were able to execute arbitrary code.
Zewnang Zhou team509 and Liang Chen of the Keen team managed to break Adobe Flash with a vulnerability heap overflow and a detour of the sandbox.
The total prize money awarded so far in Pwn2Own 2014, excluding the amount allocated for charity, comes to $850.000. Of course all vulnerabilities points have been disclosed to the development companies.