ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Researchers earned $1M+ for 58 zero-day exploits at Pwn2Own Toronto 2023

The researchers were also able to hack a fully patched Samsung Galaxy S23 four times

Kyle by Kyle
October 28, 2023
in Exploits
Reading Time: 2 mins read
p2o 1200
Share on FacebookShare on Twitter

The Pwn2Own Toronto 2023 hacking competition recently concluded, with security researchers securing $1,038,500 for 58 zero-day exploits and multiple bug collisions targeting a range of consumer products over four days in late October.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

Organized by Trend Micro’s Zero Day Initiative (ZDI), this event was primarily focused on mobile and IoT devices. Notable targets included mobile phones like the Apple iPhone 14, Google Pixel 7, Samsung Galaxy S23, and Xiaomi 13 Pro, along with printers, wireless routers, network-attached storage (NAS) devices, home automation hubs, surveillance systems, smart speakers, and Google’s Pixel Watch and Chromecast devices. All devices were in their default configurations and running the latest security updates.

Although no teams attempted hacks on the Apple iPhone 14 and Google Pixel 7 smartphones, the Samsung Galaxy S23 faced four successful breaches. The Pentest Limited team was the first to demonstrate a zero-day vulnerability in the Galaxy S23, exploiting an improper input validation flaw for code execution, earning $50,000 and 5 Master of Pwn points. The STAR Labs SG team also utilized a permissive list of allowed inputs to hack the same device, earning $25,000 in the first round and half the prize in the second, along with 5 Master of Pwn points.

Pwn2Own Toronto 2023 leaderboard
Pwn2Own’s 2023 leader board – credits to ZDI

Additional security researchers from Interrupt Labs and the ToChim team also managed to breach the Galaxy S22 on the second day by exploiting permissive input lists and another improper input validation weakness.

Team Viettel emerged as the competition’s winner, earning $180,000 and 30 Master of Pwn points. They were followed by Team Orca of Sea Security with $116,250 (17.25 points), and DEVCORE Intern and Interrupt Labs, each earning $50,000 and 10 points.

In total, the security researchers successfully demonstrated exploits targeting 58 zero-day vulnerabilities across devices from various vendors, including Xiaomi, Western Digital, Synology, Canon, Lexmark, Sonos, TP-Link, QNAP, Wyze, Lexmark, and HP.

Vendors now have 120 days to release patches for zero-day vulnerabilities exploited during the Pwn2Own event before ZDI discloses them publicly. The Pwn2Own Vancouver 2023 competition in March saw competitors earn $1,035,000 and a Tesla Model 3 car for identifying 27 zero-day vulnerabilities and experiencing several bug collisions.

Previous Post

Apple Fixes an Old IOS Bug That Let Nearby Wireless Routers Gather Real Mac Addresses

Next Post

Update Your Apple Devices Now!

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.