The Pwn2Own Berlin 2025 hacking competition has concluded, with security researchers earning $1,078,750 after exploiting 29 zero-day vulnerabilities and encountering some bug collisions. Throughout the contest, they targeted enterprise technologies in the AI, web browser, virtualization, local privilege escalation, servers, enterprise applications, cloud-native/container, and automotive categories. According to Pwn2Own's rules, all targeted devices had all security updates installed and ran the latest operating system versions. While Tesla also provided two 2025 Tesla Model Y and 2024 Tesla Model 3 bench-top units, security researchers who joined the contest haven't registered any attempts in this category before Pwn2Own started. Competitors collected $260,000 in cash awards after the first day and another $435,000 on the second day after exploiting 20 zero-day vulnerabilities. On the third day of Pwn2Own, they collected another $383,750 for eight more zero-days. After these vulnerabilities are demoed during Pwn2Own events, vendors have 90 days to release security updates before TrendMicro's Zero Day Initiative publicly discloses them. The STAR Labs SG team won this year's edition of Pwn2Own Berlin with 35 Master of Pwn points and $320,000 earned throughout the three-day contest after hacking Red Hat Enterprise Linux, Docker Desktop, Windows 11, VMware ESXi, and Oracle VirtualBox. STAR Labs' Nguyen Hoang Thach won the competition's highest reward of $150,000 after using an ...
Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin
BleepingComputer
·Sergiu Gatlan
·Published May 19, 2025
·Updated
Affected Software
14 affected components
Mozilla Firefox=138.0.4
Mozilla Firefox ESR=128.10.1
Mozilla Firefox ESR=115.23.1
Mozilla Firefox for Android
VMware ESXi
Microsoft SharePoint
Microsoft Windows=11
Red Hat Enterprise Linux
Oracle VirtualBox
Docker Desktop
Tesla Model Y=2025
Tesla Model 3=2024
Tesla Model Y=2025
Tesla Model 3=2024
Frequently Asked Questions
1
What was the total prize money awarded at Pwn2Own Berlin?
Participants earned a total of $1,078,750 for exploiting 29 zero-day vulnerabilities.
2
Which major software was targeted during the Pwn2Own Berlin competition?
The competition targeted various software including Mozilla Firefox, VMware ESXi, Microsoft SharePoint, and Docker Desktop.
3
What type of vulnerabilities were primarily demonstrated by researchers?
Researchers demonstrated the exploitation of zero-day vulnerabilities during the competition.
4
How many zero-day vulnerabilities were successfully exploited at the event?
A total of 29 zero-day vulnerabilities were successfully exploited by participants.
5
Which specific versions of Firefox were affected in the competition?
Affected versions of Firefox included 138.0.4 and the ESR versions 128.10.1 and 115.23.1.