Two Zero-Day Vulnerabilities Discovered in Safari for Mac on Day One of Pwn2Own Hacking Contest

by

The 19th annual CanSecWest security conference is underway in Vancouver, Canada, including the annual Pwn2Own hacking contest, and two zero-day security vulnerabilities have so far been discovered in Safari on macOS.

pwn2own cama zhu
The contest kicked off on Wednesday with security researchers Amat Cama and Richard Zhu teaming up against Safari. The duo successfully exploited the browser and escaped the sandbox by using a combination of an integer overflow, heap overflow, and brute force technique, earning them $55,000.

Later in the day, a trio of Niklas Baumstark, Luca Todesco, and Bruno Keith targeted Safari with a kernel elevation. They demonstrated a complete system compromise, but it was only a partial win since Apple supposedly already knew of one of the bugs used in the demo. They still netted $45,000.


In total, participants were awarded $240,000 on day one of Pwn2Own. Day two of the contest is currently underway. All exploits discovered during the contest are reported to the necessary companies like Apple so they can be patched.

Top Rated Comments

keysofanxiety Avatar
22 months ago

Seems like every other month some kid finds an exploit in Apple software. Yes - I know no software is perfect, but you’d think the world’s richest company could do better.

At least hire these kids, good grief.

You know these "kids" do this for a living and the entire purpose of the contest – the whole reason it's there – is to find vulnerabilities in software? Be that from Apple, Google, Microsoft, or applications like VMWare and VirtualBox...

Also, they get paid for it. Quite a lot.

Good grief indeed.
Score: 17 Votes (Like | Disagree)
M.PaulCezanne Avatar
22 months ago
Seems like every other month some kid finds an exploit in Apple software. Yes - I know no software is perfect, but you’d think the world’s richest company could do better.

At least hire these kids, good grief.
Score: 12 Votes (Like | Disagree)
Peepo Avatar
22 months ago

Seems like every other month some kid finds an exploit in Apple software. Yes - I know no software is perfect, but you’d think the world’s richest company could do better.

At least hire these kids, good grief.

These are not kids. They probably make more money doing this instead of working for a company like Apple.
Score: 10 Votes (Like | Disagree)
69Mustang Avatar
22 months ago

Seems like every other month some kid finds an exploit in Apple software. Yes - I know no software is perfect, but you’d think the world’s richest company could do better.

At least hire these kids, good grief.

What these guys do - (intentionally hunting vulnerabilities) - and what that kid did regarding FaceTime - (accidentally stumbled upon a vulnerability) - are not the same thing. Most of them are already gainfully employed.
Score: 5 Votes (Like | Disagree)
69Mustang Avatar
22 months ago

but at least in the past they were using older versions of Apple's software, especially older versions of Safari, and the tricks they pulled couldn't be replicated in current versions.
so I would be curious to see deets on what they were actually trying to hack

also how many of these tricks could actually be performed IRL. can they remotely access my computer etc. or do they need access to my actual computer to target me.

I don't think that's right. Afaik, Pwn2Own has always required the most up to date versions of software to be running on systems. Again, afaik. Also, these aren't really tricks. There are different categories of devices they're trying to defeat. One that may be relevant to your IRL query is the attempt against Tesla that's happening today.

Direct info: https://www.thezdi.com/blog/2019/1/14/pwn2own-vancouver-2019-tesla-vmware-microsoft-and-more
Score: 2 Votes (Like | Disagree)
Analog Kid Avatar
22 months ago
I know the threat environment is changing, and the systems are getting more complex, and Apple is under more scrutiny than ever before, but it still feels like Apple's security cred is slipping.

I appreciate all of the work they're doing on privacy, but in this world these kinds of attacks are the biggest threats to privacy. They really need to keep security as a top priority.

Also: I appreciate the structure of this event. Hack like crazy and keep the companies in the loop.
Score: 1 Votes (Like | Disagree)

Top Stories

apple briefcase

AppleCare Memo Hints at Potential Hardware Announcement Next Tuesday

Thursday December 3, 2020 9:12 am PST by
Following a busy fall season in which Apple hosted three events in as many months, the company may have one more product announcement in store this year. In an internal memo this week, obtained by MacRumors from a reliable source, Apple informed service providers that it has AppleCare-related changes planned for Tuesday, December 8 at approximately 5:30 a.m. Pacific Time. Specifically, Apple ...
iphone11colorswhitebg

Apple Launches iPhone 11 Display Module Replacement Program

Friday December 4, 2020 3:22 pm PST by
Apple today launched a new display replacement program for iPhone 11 devices to address a problem that cases a "small percentage" of iPhone 11 displays to stop responding to touch. Apple says that affected devices were manufactured between November 2019 and May 2020, and if there are touch issues, the iPhone 11 models could have a problem with the display module. Those with iPhone 11...
matte black macbook pro colorware

Apple Researching a Matte Black Finish for MacBooks

Friday December 4, 2020 9:04 am PST by
Apple has filed a patent application for an intense light-absorbant matte black finish for a range of products, including the iPhone, iPad, Apple Watch, and MacBook (via Patently Apple). Image via ColorWare The patent application, filed with the U.S. Patent and Trademark Office, is titled "Anodized Part Having a Matte Black Appearance," and outlines the characteristics of the finish and...
homepod mini amazon echo size

$99 Speaker Showdown: HomePod Mini vs. Amazon Echo and Google Nest Audio

Wednesday December 2, 2020 3:12 pm PST by
Apple recently released the HomePod mini, a new $99 version of the original HomePod that's smaller, cuter, and, most importantly, competitively priced. At $99, the HomePod mini can better compete with affordable smart speakers from companies like Google and Amazon. Subscribe to the MacRumors YouTube channel for more videos. The HomePod mini has been praised for its high-quality sound at its...
wristcam design

$299 'Wristcam' Adds a Pair of Cameras to Your Apple Watch

Thursday December 3, 2020 9:32 am PST by
The Apple Watch has never included a camera, likely due to battery life and space concerns. A new Apple Watch product aims to address that lack by introducing a wrist-worn camera that works with the Apple Watch. The Apple-certified Wristcam attaches to the Apple Watch in the form of a band that adds a rather large camera set to the top of the Apple Watch. It's quite thick and bulky, but can...
iphone 12 5g

Multiple iPhone 12 Users Report Sudden Drops in 5G and LTE Cellular Coverage

Thursday December 3, 2020 1:18 am PST by
Since Apple launched the iPhone 12 in October, an increasing number of users of the new smartphone have been reporting persistent drops in cellular coverage. Multiple reports of dropped 5G and LTE connectivity have appeared on Reddit, on Apple's support forums, and on the MacRumors forums, with many people suffering issues when walking or in transit and some seeing the same problem when...
iOS 14

Apple Releases Third Betas of iOS 14.3 and iPadOS 14.3 to Developers [Update: Public Beta Available]

Wednesday December 2, 2020 10:04 am PST by
Apple today seeded the third betas of upcoming iOS 14.3 and iPadOS 14.3 updates to developers for testing purposes, two weeks after releasing the second betas and a month after the launch of iOS and iPadOS 14.2. iOS and iPadOS 14.3 can be downloaded through the Apple Developer Center or over the air after the proper developer profile has been installed. The iOS 14.3 update brings the...
16 inch MBP Mini Led

Kuo: Two Redesigned MacBook Pros in 2021 and New MacBook Air in 2022, All With Apple Silicon and Mini-LED Displays

Wednesday December 2, 2020 5:46 am PST by
Apple plans to release two redesigned MacBook Pros in 2021 and a new MacBook Air in 2022, all with mini-LED displays and Apple Silicon chips, according to TFI Securities analyst Ming-Chi Kuo. In a research note to investors, seen by MacRumors, Kuo explained that two new MacBook Pro models equipped with an all-new form factor design are expected to launch in 2021, and a new "affordable"...
satechi magnetic charger

Satechi Debuts Magnetic Wireless Charger for iPhone 12 Models

Friday December 4, 2020 8:00 am PST by
Satechi today announced a new USB-C Magnetic Wireless Charging Cable, which is a new wireless charging option for Apple's iPhone 12 models. Designed to work with the magnets built into the iPhone 12 lineup, the Magnetic Wireless Charging Cable adheres to the back of an iPhone much like Apple's MagSafe charger. The Magnetic Wireless Charging Cable works attaches to an iPhone 12 with a...
magsafe duo design

Hands-On With Apple's New MagSafe Duo Charger for iPhone 12 and Apple Watch

Thursday December 3, 2020 2:49 pm PST by
Apple on Tuesday finally released the MagSafe Duo Charger, which is a $129 charger that combines an iPhone 12 MagSafe charger with an Apple Watch charging puck. Subscribe to the MacRumors YouTube channel for more videos. We picked up one of the new MagSafe Duo chargers to see if it's worth Apple's super high asking price. Apple first introduced the MagSafe Duo alongside the new iPhone 12...