Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Browsers go boom: Pwn2Own hackers take down Chrome, Firefox, & Internet Explorer

Add as a preferred source on Google
chrome-dead_dt
Image used with permission by copyright holder

Think the browser your just updated is safe? Nope. Time to pack up the Internet and go home – nowhere is safe anymore. Hackers from France and the UK have cracked Chrome, Firefox, and Internet Explorer and used them to take control of their host computers. The good news? This was only a test. 

The Pwn2Own competition held during the CanSecWest security conference in Vancouver, Canada, awards money to the fastest hackers, and, as you might expect, the hackers turn over their methods and information used to exploit the browsers’ weaknesses. According toZDNet, a French security firm, Vupen, took down both Internet Explorer 10 and Firefox, while MWR Labs, a UK-based security firm, took down Chrome. All of the browsers had recent updates and patches applied to them, so it was no different than the most recent updated version of the browser on your desktop.

Recommended Videos

So how did they do it? This is where it gets extra tech-speaky. Vupen announced on Twitter that they cracked Internet Explorer 10. “We’ve pwned MS Surface Pro with two IE10 zero-days to achieve a full Windows 8 compromise with sandbox bypass#Pwn2own.” In English: they used two previously unknown holes in Internet Explorer 10 to gain access to Windows 8 on a Surface Pro tablet.

As for how Vupen cracked Firefox, Venture Beat explains it as a method that “involves recalling memory that the browser had previously ‘freed,’ (user-after-free), after which they were able to mess with the technology that protects a computer system from letting bad code execute.”

As if it wasn’t enough that two browsers fell, MWR Labs was able to take down the newest version of Google’s browser, Chrome 25, which just received a bushel full of security updates and patches. Chrome was defeated on a Windows 7 machine by exploiting the sandbox feature of the browser, which, ironically, is supposed to keep your computer safer. 

So what happens now that three major browsers have been exposed as vulnerable? Microsoft, Mozilla, and Google take the hacker’s how-tos and use the information to patch security holes and end up with stronger, safer browsers. 

Meanwhile, other browsers and Web applications are also being put to the test at CanSecWest with somewhat better results. No one was able to crack Safari running in OS X 10.8 Mountain Lion. Additionally, Adobe Flash and Reader on Windows 7 both held up, though hackers at the conference are still working on taking those apps down today.

Lastly, the one app that got kicked around like an old can during the Pwn2Own competition was Java. It was cracked three different times, including once by Vupen. Be careful out there. 

Meghan McDonough
Former Contributor
Meghan J. McDonough is a Chicago-based purveyor of consumer technology and music. She previously wrote for LAPTOP Magazine…
Topics
Your favorite Edge extension may stop working soon as Microsoft follows Chrome’s lead
Microsoft has announced the transition to Manifest V3, gradually phasing out older browser extensions.
Microsoft Edge on PC and Mobile Featured

Microsoft Edge is finally making the same controversial move that Google Chrome did earlier this year, and it could mean the end of some of the browser's most popular ad blockers. Microsoft has announced that Edge is officially transitioning its extensions ecosystem to Manifest Version 3 (MV3), Google's newer extension platform that promises better security, privacy, and performance. As part of that shift, the browser will gradually stop supporting older Manifest V2 (MV2) extensions over the coming months, meaning legacy extensions such as the original uBlock Origin will eventually stop working in Edge.

What is Manifest V3, and why is Microsoft adopting it?

Read more
Help, I’m talking to my computer. It’s remarkably convenient and utterly embarrassing.
Oh look, I have become the guy who randomly starts talking while staring at his computer.
Person using a laptop.

A decade ago, Google introduced voice typing with the Gboard app on Android, and a year later, the perk landed on iPhones with the keyboard app. I never paid much attention to it. The biggest reason was that it was just not accurate. 

The big promise was a whole new way of interacting with our phones, but it was never good enough to make me quit tapping, or swiping on an on-screen keyboard. Fast forward to 2026, I'm talking to my computer. In fact, this whole article was dictated and copy-pasted in WordPress. 

Read more
Cloudflare’s new browser Kitesurf is designed for AI agents to browse the internet
AI agents just got their own browser that lets them browse the internet more efficiently.
cloudflare-kitesurf-browser-for-ai

Cloudflare just entered the AI-browser race with a twist. Instead of building another Chrome alternative for people, the company launched Kitesurf, a cloud-hosted browser made only for AI agents. Since autonomous AI systems are increasingly the ones doing the actual browsing and scrolling online, Cloudflare just made its to claim that space.

https://twitter.com/Cloudflare/status/2085372860650913898

Read more