Skip to main content

Microsoft Edge browser fails to fend off five attacks at Pwn2Own hacking event

exploit
Image used with permission by copyright holder
One of the premier hacking contests is Pwn2Own, where security teams get together and see if they can break into the leading operating systems and web browsers. The 2017 version of Pwn2Own is now in the past, and Microsoft’s Edge is the loser.

Edge is an important browser for Microsoft, representing the next generation of Windows web browser that’s intended to take over from Internet Explorer. Microsoft has touted Edge as safer than Google’s Chrome and Mozilla’s Firefox, but Pwn2Own has thrown that assertion into doubt, as Tom’s Hardware reports.

At last year’s event, Chrome took home the prize by only suffering from one partial hack. Edge was in second place with two hacks, which edged out (no pun intended) both Microsoft’s own Internet Explorer and Safari. This year, on the other hand, Edge was hacked a full five times, due to a number of vulnerabilities in systems ranging from the Chakra Javascript engine to a bug in the Windows kernel.

By far the worst hack, however, was an exploit by the 360 Security team that actually managed to escape a virtual machine and attack its host, which had never happened at Pwn2Own. This kind of attack is particularly troublesome, given that one of the very reasons for running a virtual machine is to sandbox an environment and keep host machines safe.

The 360 Security team netted a cool $105,000 for the exploit. Other prizes included $80,000 for Team Ether’s Chakra exploit and $55,000 for Team Lance’s Windows kernel elevation hack. Of all the browsers, Edge was the most lucrative in terms of money awarded.

Safari was a bit more secure than Edge, with three hacks including one that provided root access to MacOS. Firefox made its way back to Pwn2Own after a yearlong hiatus, and its newly implemented sandbox technology helped it take second place with just two successful hacks. Chrome was again the event’s most secure browser, without a single successful hack against it and only one attempt.

While Pwn2Own doesn’t make any real attempt at fairness by ensuring that every browser is attacked an equal number of times, it’s obvious that Microsoft still has some work to do with Edge. Given its prominence in Windows 10, and the company’s commitment to making its latest OS the most dominant desktop environment ever, Edge needs to live up to Microsoft’s billing as the safest browser if it’s going to gain in market share.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
How to double space in Microsoft Word
Overhead view of someone typing on a Surface laptop.

Double-spacing is a great way to organize your word processing, and an excellent optimization that is built into most word processing tools. And whenever we hear “word processing,” one of the first programs that comes to mind is Microsoft Word. This handy software has been around for a minute, and we’re going to teach you how to implement double spaces throughout your next Word doc.

Read more
5 web browsers you should use instead of Google Chrome or Edge
Google Drive in Chrome on a MacBook.

Google Chrome and Microsoft Edge dominate the world of web browsers, but they’re not for everyone. Whether you want a browser that better respects your privacy or need an app that does things a little bit differently, you don’t have to stick to the usual suspects.

There’s a world of alternative web browsers out there if you want to give something new a try. Here, we’ve put together five excellent options, with each one bringing fresh new ideas to the table. So, if you’re sick of Chrome and Edge, take one of these browsers for a spin.
Arc
Easels let you pin live websites snippets, which can update themselves and be interacted with. Alex Blake / Digital Trends

Read more
Windows 11 Home usually costs $139 — but it’s only $30 today
Laptop sitting on a desk showing Windows 11's built-in Microsoft Teams experience

If you've recently bought yourself a new desktop or laptop, you're most likely using Windows 11 Home edition, which is still pretty good, but it does lock some features away that you can only get with the Pro edition. While they aren't completely necessary, they are nice to have, but the usual $200 cost of a Windows 11 Pro license means they aren't worth the cost. Luckily, there's a great deal from StackSocial that discounts Windows 11 Pro down to just $30, which constitutes a whopping 84% discount on the regular price. You better grab it quite too, because the sale is going to be ending soon.

Why you should buy Microsoft Windows 11 Pro
Most of the features that you'll find on Windows 11 Pro are targeted to, you guessed it, professionals, but that doesn't mean that you can't also take advantage of it. For example, while both versions of Windows 11 are pretty secure, Windows 11 Pro has extra security features. For example, the Pro version comes with Defender Application Guard, which is an additional level of security that protects your files even if your computer is stolen, and the BitLocker can directly lock your files so nobody can read them even if they can access them.

Read more