Particle.news

Download on the App Store

Pwn2Own Berlin 2025 Wraps with Record $1.1 Million in Prizes and Critical Exploits Unveiled

StarLabs SG claims 'Master of Pwn' title, while vendors rush to patch 28 zero-day vulnerabilities revealed during the competition.

Image
Image
Image

Overview

  • The inaugural European edition of Pwn2Own, held alongside OffensiveCon in Berlin, saw researchers disclose and sell 28 zero-day vulnerabilities across critical platforms.
  • StarLabs SG from Singapore emerged as the overall winner, earning the 'Master of Pwn' title and $320,000 in prize money.
  • Breakthrough exploits included the first single integer overflow takeover of VMware ESXi and dual JavaScript-based hacks of Firefox, leading Mozilla to release urgent patches (Firefox 138.0.4 and ESR updates).
  • A newly introduced AI category targeted platforms like Nvidia Triton Inference Server and Redis, reflecting a shift toward securing machine-learning infrastructure.
  • Vendors, including Mozilla and VMware, have begun rolling out updates to address vulnerabilities, underscoring the rapid response cycle following the competition.