Researchers Uncover macOS and Safari Exploits at Pwn2Own 2017

… Day one results have already been published over at the Zero Day Initiative website, with a couple of successful Mac-related exploits already appearing in the list of achievements. Independent hackers Samuel Groß and Niklas Baumstark landed a partial success and earned $28,000 after targeting Safari with an escalation to root on macOS, which allowed them to scroll a message on a MacBook Pro Touch Bar. …

Later in the day, Chaitin Security Research Lab also targeted Safari with an escalation to root on macOS, finding success using a total of six bugs in their exploit chain, including “an info disclosure in Safari, four type confusion bugs in the browser, and a UAF in WindowServer”. The combined efforts earned the team $35,000. …

The participating teams earned a total of $233,000 in prizes on day one, including a leading $105,000 earned by Tencent Security, according to published details. Other software successfully targeted by contestants include Adobe Reader, Ubuntu Desktop, and Microsoft Edge on Windows. …

Source: Researchers Uncover macOS and Safari Exploits at Pwn2Own 2017

Share

Leave a Reply