The second day of Pwn2Own Vancouver 2023, the famous hacking contest organized by the Zero Day Initiative (ZDI), has ended.
The competition started on March 23 and saw dozens of hackers attempting to find vulnerabilities in popular software and operating systems, including Microsoft Edge, Google Chrome, Apple Safari, and Ubuntu.
On day two, participants focused on testing the security of the macOS and Windows 10 operating systems with some success.
For macOS, a team of researchers from the Georgia Tech Systems Software and Security Lab successfully exploited a Safari browser vulnerability, earning them $40,000 in prize money. Meanwhile, another team of researchers from the same lab won $20,000 for successfully using a macOS kernel vulnerability.
On the Windows 10 side, Team Fluoroacetate, composed of hackers Amat Cama and Richard Zhu, successfully exploited a Windows 10 virtual machine, earning them $80,000 in prize money. The duo also won an additional $20,000 for exploiting Microsoft Edge.
Other participants attempted to find vulnerabilities in the Ubuntu operating system but were unsuccessful.
In total, the second day of Pwn2Own Vancouver 2023 awarded $200,000 in prize money to the participating teams. The competition will continue on March 24 with further attempts to exploit various software and operating systems.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 14, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.