Chinese hacker cracks Safari, wins $62.5K, praises Apple's security

March 14, 2014: 12:07 PM ET

Some of his prize money will go to families of the missing Malaysian airline.


Keen Team's Chen, right, demos an exploit to HP's Joshua Smith

FORTUNE -- Everybody's Web software got "pwned" at the Pwn2Own hackers conference this week: Apple's (AAPL) Safari, Google's (GOOG) Chrome, Microsoft's (MSFT) Internet Explorer, Mozilla's Firefox and Adobe's (ADBE) Reader and Flash.

Chrome was hacked by a French team from Vupen Security with a use-after-free vulnerability that affects both the WebKit and Blink rendering engines.

Safari was defeated by Liang Chen, one of a pair Chinese Keen Team hackers, using a heap-overflow-and-sandbox-bypass combination that took three months to perfect.

"For Apple, the OS is regarded as very safe and has a very good security architecture," Chen told ThreatPost's Michael Mimoso. "Even if you have a vulnerability, it's very difficult to exploit. Today we demonstrated that with some advanced technology, the system is still able to be pwned. But in general, the security in OS X is higher than other operating systems."

In a separate interview with CNET, Chen said that OS X is harder to attack than iOS 7.0 because Apple issues security updates for its desktop operating system more frequently than for its mobile OS.

The two-day event, sponsored by Hewlett-Packard (HPQ) and organized by the HP-owned Zero-Day Initiative, paid out $850,000 in prize money to eight teams of competitors, plus another $82,500 in charitable donations. The event was staffed by observers from Apple and the other companies, which will presumably now start patching those holes.

"I think the Webkit fix will be relatively easy," Chen told Mimoso. "The system-level vulnerability is related to how they designed the application; it may be more difficult for them."

CORRECTION: An earlier version of this story had the prize money wrong. Keen Team won $62,500 for pwning Safari and another $75,000 for an Adobe Flash exploit for a total of $137,500. Source: Pwn2Own 2014: Rules and Unicorns 

  • Apple's newest vice president: Bozo or rising star?

    Adobe's Kevin Lynch comes to Apple with deep roots and a lot of baggage

    FORTUNE -- The news that Apple (AAPL) has hired Kevin Lynch, formerly Adobe's (ADBE) chief technology officer, to be its new vice president of technology, has sparked something of a civil war among Apple partisans.

    Wired's Steve Levy called Lynch a "star."

    Daring Fireball's John Gruber called him a "bad hire" and a "bozo."

    "Now we find out," tweeted Dave MORE

    - Mar 20, 2013 7:06 AM ET
  • Adobe CTO: Android will run majority of smartphones by Spring

    Also mobile broadband will surpass wireline speeds in the next three years or so.

    If you think Gartner and IDC are bullish on Android, talk to Adobe (ADBE) CTO Kevin Lynch for a few minutes.  In an interview on Monday, Lynch told Fortune that he believes that Android's growth will continue to blow past the industry and will make up 50% of the smartphone market within the next six months.

    In the MORE

    - Nov 10, 2010 1:41 PM ET
  • Today in Tech

    Every day, the Fortune staff spends hours poring over tech stories, posts, and reviews from all over the Web to keep tabs on the companies that matter. We've assembled the day's most newsworthy bits below.

    Paul Rademacher, maker of "the first true Web 2.0 application," is leaving Google. Rademacher, an engineering manager for Google Maps, made his name with HousingMaps.com, which mashed up Google Maps with Craigslist data. (TechWhack)
    Oracle MORE

    - Nov 3, 2010 8:13 AM ET
  • How to see Flash on an iPhone

    Skyfire CEO Jeffrey Glueck explains how his newly approved browser works


    The Skyfire browser, which has been downloaded more than 1.5 million times on Google (GOOG) Android devices, has just been approved as an application for Apple's (AAPL) App Store. It goes on sale at 9 a.m. EDT Thursday for $2.99.

    The app gets around Apple's restrictions against Adobe (ADBE) Flash by converting Flash videos into an HTML5 format suitable for viewing MORE

    - Nov 2, 2010 1:57 PM ET
  • Today in Tech: News around the Web

    Every day, the Fortune staff spends hours poring over tech stories, posts, and reviews from all over the Web to keep tabs on the companies that matter. We've assembled the day's most newsworthy bits below.

    Surprise, naysayers! Microsoft posted a record first quarter: $5.41 billion in earnings and $16.2 billion in revenue -- in particular, sales were up 25%. CFO Peter Klein said in a statement that it was an exceptional MORE

    - Oct 29, 2010 8:11 AM ET
  • Flash on Android beats HTML5 on Android or iOS?

    Adobe says that their Flash Mobile app is not only faster than HTML5 but it also uses less power.

    Adobe Blogger John Nack posts a video today comparing Flash 10.1 and HTML5 on the eight month old Nexus One and then compares it with the just-released iPod touch which runs the same processor as the iPhone 4.  The original tests can be seen here (and I've run them and got similar MORE

    - Sep 18, 2010 4:22 PM ET
    Posted in: , , , ,
  • Adobe on Apple: Our glass is half full

    Flash apps are already getting approved, but there's still no Flash in the mobile browser

    Confusion reigned for much of Thursday following Apple's (AAPL) announcement that it was lifting its restrictions on development tools for iPhone apps.

    Wall Street, assuming that this meant that Adobe (ADBE) has won its long-running Flash battle with Steve Jobs, drove the company's stock price sharply higher. Adobe closed the day at $32.86, up $3.55 (12.11%).

    Developers, meanwhile, MORE

    - Sep 10, 2010 7:31 AM ET
  • Why did Apple lift its ban on apps written in Flash?

    Steve Jobs once called Flash the No. 1 reason his devices crash. What changed his mind?

    With a terse, five-paragraph statement issued Thursday morning, Apple (AAPL) reversed a five-month-old policy that had sparked an industry-wide debate, a government probe and tens of thousands of words of heated commentary -- including Steve Jobs' own April 2010 "Thoughts on Flash."

    The newly inoperative policy had prohibited software developers from using cross-platform tools when MORE

    - Sep 9, 2010 10:24 AM ET
  • India's $35 Android tablet for developing world

    Prices could drop to an absurd $10-$20 when these hit scale.

    Today, India's human resource development minister, Kapil Sibal, unveiled a $35 tablet computer that will run Linux.  Although it wasn't specified, the device he displayed had the familiar notification icons of Android, seen to the right.  Android, is a Linux OS built for smartphones and now tablets by Google under an Open Source license.

    "This is our answer to MIT's $100 MORE

    - Jul 23, 2010 3:44 PM ET
    Posted in: , , ,
Current Issue
  • Give the gift of Fortune
  • Get the Fortune app
  • Subscribe
Powered by WordPress.com VIP.