Researchers Uncover macOS and Safari Exploits at Pwn2Own 2017

The seventeenth annual CanSecWest security conference is underway in downtown Vancouver, British Columbia, where researchers are competing in the 10th anniversary Pwn2Own computer hacking contest for over $1 million in prizes.

Day one results have already been published over at the Zero Day Initiative website, with a couple of successful Mac-related exploits already appearing in the list of achievements. Independent hackers Samuel Groß and Niklas Baumstark landed a partial success and earned $28,000 after targeting Safari with an escalation to root on macOS, which allowed them to scroll a message on a MacBook Pro Touch Bar.

In a partial win, Samuel Groß (@5aelo) and Niklas Baumstark (@_niklasb) earn some style points by leaving a special message on the touch bar of the Mac. They used a use-after-free (UAF) in Safari combined with three logic bugs and a null pointer dereference to exploit Safari and elevate to root in macOS. They still managed to earn $28,000 USD and 9 Master of Pwn points.

Later in the day, Chaitin Security Research Lab also targeted Safari with an escalation to root on macOS, finding success using a total of six bugs in their exploit chain, including “an info disclosure in Safari, four type confusion bugs in the browser, and a UAF in WindowServer”. The combined efforts earned the team $35,000.

The participating teams earned a total of $233,000 in prizes on day one, including a leading $105,000 earned by Tencent Security, according to published details. Other software successfully targeted by contestants include Adobe Reader, Ubuntu Desktop, and Microsoft Edge on Windows.

Apple representatives have attended the Pwn2Own contest in the past, and affected parties are made aware of all security vulnerabilities discovered during the contest in order to patch them. Pwn2Own day two begins today at 8:30 a.m. Pacific and will involve additional exploit attempts against macOS and Safari.

Discuss this article in our forums


Source From: macrumors.com.
Original article title: Researchers Uncover macOS and Safari Exploits at Pwn2Own 2017.
This full article can be read at: Researchers Uncover macOS and Safari Exploits at Pwn2Own 2017.

Advertisement


Random Article You May Like

  • A Billion Is Cool

    Yesterday, the NuGet team announced that NuGet.org reached one billion package downloads! It’s exciting to see NuGet still going strong. […]

  • Casper: Raccourcisseurs d'URL

    Ah les raccourcisseurs d’URL, les TinyURL et les BitLy, quelle belle invention. Initialement inventés pour pouvoir retaper rapidement à la […]

  • Jonathan Dieter: Flock 2018

    Dresden Last week, I had the opportunity to be at Flock, Fedora’s contributer conference, in Dresden. As I was preparing […]

  • Kushal Das: Tor Mumbai meetup

    On 20th January, we had a Tor meetup in Mumbai. Hasgeek organized the event, with OML providing the meeting space. […]

Leave a Reply

Your email address will not be published. Required fields are marked *

*
*