Skip to main content

Microsoft Edge browser fails to fend off five attacks at Pwn2Own hacking event

exploit
Image used with permission by copyright holder
One of the premier hacking contests is Pwn2Own, where security teams get together and see if they can break into the leading operating systems and web browsers. The 2017 version of Pwn2Own is now in the past, and Microsoft’s Edge is the loser.

Edge is an important browser for Microsoft, representing the next generation of Windows web browser that’s intended to take over from Internet Explorer. Microsoft has touted Edge as safer than Google’s Chrome and Mozilla’s Firefox, but Pwn2Own has thrown that assertion into doubt, as Tom’s Hardware reports.

At last year’s event, Chrome took home the prize by only suffering from one partial hack. Edge was in second place with two hacks, which edged out (no pun intended) both Microsoft’s own Internet Explorer and Safari. This year, on the other hand, Edge was hacked a full five times, due to a number of vulnerabilities in systems ranging from the Chakra Javascript engine to a bug in the Windows kernel.

By far the worst hack, however, was an exploit by the 360 Security team that actually managed to escape a virtual machine and attack its host, which had never happened at Pwn2Own. This kind of attack is particularly troublesome, given that one of the very reasons for running a virtual machine is to sandbox an environment and keep host machines safe.

The 360 Security team netted a cool $105,000 for the exploit. Other prizes included $80,000 for Team Ether’s Chakra exploit and $55,000 for Team Lance’s Windows kernel elevation hack. Of all the browsers, Edge was the most lucrative in terms of money awarded.

Safari was a bit more secure than Edge, with three hacks including one that provided root access to MacOS. Firefox made its way back to Pwn2Own after a yearlong hiatus, and its newly implemented sandbox technology helped it take second place with just two successful hacks. Chrome was again the event’s most secure browser, without a single successful hack against it and only one attempt.

While Pwn2Own doesn’t make any real attempt at fairness by ensuring that every browser is attacked an equal number of times, it’s obvious that Microsoft still has some work to do with Edge. Given its prominence in Windows 10, and the company’s commitment to making its latest OS the most dominant desktop environment ever, Edge needs to live up to Microsoft’s billing as the safest browser if it’s going to gain in market share.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
The best tablets in 2024: top 11 tablets you can buy now
Disney+ app on the iPad Air 5.

As much as we love having the best smartphones in our pockets, there are times when those small screens don't cut it and we just need a larger display. That's when you turn to a tablet, which is great for being productive on the go and can be a awesome way to unwind and relax too. While the tablet market really took off after the iPad, it has grown to be quite diverse with a huge variety of products — from great budget options to powerhouses for professionals.

We've tried out a lot of tablets here at Digital Trends, from the workhorses for pros to tablets that are made for kids and even seniors -- there's a tablet for every person and every budget. For most people, though, we think Apple's iPad Air is the best overall tablet — especially if you're already invested in the Apple ecosystem. But if you're not an Apple user, that's fine too; there are plenty of other great options that you'll find in this roundup.

Read more
How to delete a file from Google Drive on desktop and mobile
Google Drive in Chrome on a MacBook.

Google Drive is an excellent cloud storage solution that can be accessed from numerous devices. Whether you do most of your Google Drive uploading or downloading from a PC, Chromebook, or mobile device, there’s going to come a time when you’ll need to delete a file (or two). Fortunately, the deletion process couldn’t be more straightforward. We’ve also put together this helpful guide to show you how to trash your Drive content a couple of different ways.

Read more
Windows 11 might nag you about AI requirements soon
Copilot on a laptop on a desk.

After recent reports of new hardware requirements for the upcoming Windows 11 24H2 update, it is evident that Microsoft is gearing up to introduce a bunch of new AI features. A new report now suggests that the company is working on adding new code to the operating system to alert users if they fail to match the minimum requirements to run AI-based applications.

According to Albacore on X (formerly known as Twitter), systems that do not meet the requirements will display a warning message in the form of a watermark. After digging into the latest Windows 11 Insider Build 26200, he came across requirements coded in the operating system for an upcoming AI File Explorer feature. The minimum requirement includes an ARM64 processor, 16GB of memory, 225GB of total storage, and a Qualcomm Snapdragon X Elite NPU.

Read more