Vulnerabilities

Tesla, OS, Software Exploits Earn Hackers $1.1 Million at Pwn2Own 2024

Exploits targeting Tesla cars, operating systems, and popular software earned participants over $1.1 million at Pwn2Own Vancouver 2024.

Pwn2Own Vancouver 2024

Exploits targeting Tesla cars, operating systems, and popular software earned participants over $1.1 million at Pwn2Own Vancouver 2024, Trend Micro’s Zero Day Initiative (ZDI) said on Thursday after the event wrapped up. 

On the first day, participants earned a total of $732,500 for 19 unique zero-day vulnerabilities found in Tesla cars, Windows, Ubuntu, Oracle VirtualBox, VMware Workstation, Chrome, Edge, and Adobe Reader. 

The highest single prize, $200,000, was awarded to the team representing cybersecurity firm Synacktiv, which also received a new Tesla Model 3 for demonstrating an exploit against the car’s electronic control unit (ECU).

On the second day, the highest reward, $100,000 went to Manfred Paul, for a Firefox exploit that involved remote code execution and a sandbox escape. The researcher was declared the winner of this Pwn2Own, earning a total of more than $200,000 after also hacking the Safari, Chrome and Edge browsers. 

Another significant reward, $85,000, was earned on the second day by Seunghyun Lee of Kaist Hacking Lab for a remote code execution exploit affecting both Chrome and Edge.

The only Docker exploit presented at Pwn2Own earned the Star Labs SG team $60,000. The same team also earned $30,000 for a VMware Workstation exploit that involved one previously known vulnerability. 

The Palo Alto Networks team received $42,500 for an exploit that works against both Chrome and Edge.

Others earned thousands of dollars for Windows 11, Ubuntu, and Oracle VirtualBox exploits. 

Advertisement. Scroll to continue reading.

A total of 29 unique zero-day vulnerabilities were demonstrated at Pwn2Own Vancouver 2024, earning participants $1,132,500. ZDI said it paid out a total of nearly $3.5 million at the last three Pwn2Own events.

Related: Tesla Hacked Twice at Pwn2Own Exploit Contest

Related: Hackers Earn $1.3M for Tesla, EV Charger, Infotainment Exploits at Pwn2Own Automotive

Related: Hackers Earn Over $1 Million at Pwn2Own Toronto 2023

Related Content

Vulnerabilities

Google pushes a new Chrome update to patch another zero-day vulnerability demonstrated at a hacking contest.

Malware & Threats

Google ships a security-themed Chrome browser refresh to fix flaws exploited at the CanSecWest Pwn2Own hacking contest.

Vulnerabilities

Firefox browser updates address two zero-day vulnerabilities exploited at the Pwn2Own hacking contest.

IoT Security

Participants earned a total of $732,500 on the first day of Pwn2Own Vancouver 2024 for hacking a Tesla, operating systems, and other software.

IoT Security

Participants have earned more than $1.3 million for hacking Teslas, EV chargers and infotainment systems at Pwn2Own Automotive.

IoT Security

Over $1 million paid out in the first two days of Pwn2Own Automotive for Tesla, infotainment and EV charger hacks.

IoT Security

On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems.

Vulnerabilities

Hackers have demonstrated 58 zero-days and earned more than $1 million in rewards at Pwn2Own Toronto 2023.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version