Skip to main content
  1. Home
  2. Mobile
  3. Legacy Archives

Pwn2Own: Safari, iPhone, IE, and Firefox All Fall

Add as a preferred source on Google
Image used with permission by copyright holder

The Pwn2Own contest at the annual CanSecWest conference in Vancouver, British Columbia has become something of a media event for security researchers, a chance for them to step out from behind glowing LCDs and demonstrate that some of the security threats they’ve hinted could impact everyday computer users are real—and pick up some cash money for their efforts. And this year, they did not disappoint: at the Pwn2Own contest, Apple’s iPhone and Safari fell first to security experts, followed in short order by Internet Explorer 8 and Firefox on Windows 7.

On the Macintosh, the star of Pwn2Own this year was again Charlie Miller of Independent Security Evaluators, who picked up the $10,000 top prize by demonstrating a takeover attack on Safari an Apple MacBook Pro that granted complete access to the machine without requiring any physical access—all the Safari user had to do was visit a Web site with malicious code. Miller won $10,000 n 2008 for breaking into a MacBook Air, and $5,000 last year by exploiting another security loophole in Apple’s Safari browser.

Recommended Videos

Dutch security researcher Peter Vreugdenhil also won $10,000 for a security exploit that bypassed security features in Microsoft’s Internet Explorer 8. A researcher from the UK’s MWR InfoSecurity named Nils—no last names, please—picked up another $10,000 for an exploit targeting Firefox on the the 64-bit version of Windows 7. Last year, Nils picked up $15,000 for a collection of exploits that targeted Firefox, Safari, and Internet Explorer 8.

Perhaops the star of the show, however, was Apple’s iPhone, which fell victim to Ralf Philipp Weinmann and Vincenzo Iozzo, of the University of Luxembourg and the German company Zynamics (respectively), who will share a $15,000 prize.

Researchers aren’t sharing the specifics of their attacks with the general public, in order to give browser and operating system developers a change to patch the loopholes. However, Miller’s attack on Safari is being described as so reliable that, in information security terms, it’s “weaponized.” Vreugdenhil’s attack on IE8 was a four-part process that exploited two separate vulnerabilities; as with Miller’s Safari attack, it launched from a user connecting to a Web site containing malicious code. Nils’ attack on Firefox exploited a memory corruption bug.

Weinmann and Iozzo’s attack on the iPhone also involved visiting a site bearing malicious code; the technique bypassed the iPhone’s code-signing requirement and could be used to access an iPhone’s SMS database, contacts, photos, or other data.

The Pwn2Own contest is sponsored by TippingPoint’s Zero Day Initiative.

As of the start of the second day of the Pwn2Own contest, Google’s Chrome 4 remains the only browser left standing…but that’s probably because it wasn’t tested at all on the first day.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
The best tutoring apps and websites
Screenshot of student studying

Whether you're thinking of learning a new language, looking for homework help, need a hand with your research paper, or could use a quick review for your upcoming SATs, a skilled tutor can help with all of the above. No longer limited to office hours or library meet-ups, online tutoring services are evolving and improving. In 2025, AI-powered study tools, mobile-first platforms, and expanded access to tutors around the world, students are able to get expert help anytime, anywhere.

Today's learners expect more than just flexibility. They want tutoring that's fast, focused, and delivers results. This shift has led to a new generation of tutoring platforms that combine on-demand help with real-time trackable progress.

Read more
Cosmo JrTrack 5 smartwatch for kids gives you peace of mind — on sale at 50% off
Three views of the Cosmo JrTrack 5 kids smartwatch.

For peace of mind, parents should take advantage of today's technology for their child's safety, and for smartwatch deals, the Cosmo JrTrack 5 is an excellent example. This smartwatch is an all-in-one kid-safe solution that you can trust for the back-to-school season, and it's available for a very affordable price of only $75 from Cosmo itself following a 50% discount on its original price of $150. We highly recommend proceeding with your purchase of this wearable device as soon as possible though, as we're not sure how much time is remaining on this amazing offer.

Buy Now

Read more
Belkin’s new iPhone chargers are great news for the Pixel 10 series
These 25W wireless MagSafe charging stands aren't just for iPhone users
Belkin UltraCharge 2in1 wireless charger on a white desk, next to a laptop

What's happened? Belkin has launched "the world’s first Qi2 25W certified wireless charging collection", for the easy wireless charging of your iPhone, Apple Watch and AirPods. But it's not just Apple's devices which will benefit from the new chargers.

Google announced its new Pixel 10 series earlier in the week, the first major Android phones to have Qi2 built-in, which means they're compatible with MagSafe accessories for iPhone.

Read more