• News/
  • bleepingcomputer-20260514185350

Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026

BleepingComputer
·
Sergiu Gatlan
·
Published May 14, 2026
·
Updated

On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days. Today's highlight was the attempt of Cheng-Da Tsai (also known as Orange Tsai) of DEVCORE Research Team, who was awarded $175,000 in rewards after chaining 4 logic bugs to achieve a sandbox escape on Microsoft Edge. Windows 11 was also hacked three times by Angelboy and TwinkleStar03 (working with the DEVCORE Internship Program), Marcin Wiązowski, and Kentaro Kawane of GMO Cybersecurity, each earning $30,000 in cash rewards for demonstrating new privilege escalation zero-days. Valentina Palmiotti (chompie) of IBM X-Force Offensive Research (XOR) also collected $20,000 after rooting Red Hat Linux for Workstations and another $50,000 for a zero-day in the NVIDIA Container Toolkit. Other successful attempts include k3vg3n chaining 3 bugs to take down LiteLLM ($40,000), Satoki Tsuji and haehae exploiting NVIDIA Megatron Bridge zero-days ($20,000), Compass Security and maitai of Doyensec hacking OpenAI's Codex coding agent (each earning $40,000), haehae dropping a Chroma zero-day ($20,000), and STARLabs SG a LM Studio zero-day ($40,000). The DEVCORE Research Team is now leading the competition with $205,000, followed by Valentina Palmiotti with $70,000. ​​The Pwn2Own Berlin 2026 hacking contest, which focuses on enterprise technologies and artificial intelligence, takes place at the OffensiveCon conference from May 14 to May 16. On the second day, ...

Read full article

Affected Software

12 affected components
Microsoft Edge
Microsoft Windows
Red Hat Linux for Workstations
Nvidia Container Toolkit
Nvidia Megatron Bridge
OpenAI Codex
Microsoft SharePoint
Microsoft Exchange
Apple Safari
Red Hat Enterprise Linux for Workstations
Anthropic Claude Code
Mozilla Firefox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the hacking event at Pwn2Own Berlin 2026 where security researchers exploited vulnerabilities in Windows 11 and Microsoft Edge.

2

What significant amount of cash was awarded at this event?

Security researchers collected a total of $523,000 in cash awards after exploiting 24 unique zero-days.

3

Who was one of the key researchers mentioned in the article?

Orange Tsai is highlighted as a key researcher who earned $175,000 by chaining four logic bugs.

4

What specific software products were affected by the exploits?

The affected software includes Microsoft Edge, Microsoft Windows 11, and various products from NVIDIA and Red Hat.

5

What is a zero-day vulnerability?

A zero-day vulnerability is a security flaw that is unknown to the vendor and can be exploited by attackers before a patch is developed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203