The Firefox 66 browser was announced on March 19, so the company let friendly hackers to attack it in order to detect any potential security vulnerabilities. The researchers identified two issues in the web browser.  On the very next day, the company decided to release a patch to fix both of them in Firefox 66.0.1 update.  Those who are not aware of Pwn2Own, it is basically an annual hacking competition. It provides a great opportunity to security researchers so that they can demonstrate new zero-day bugs. In return for their efforts, Trend Micro’s Zero Day Initiative (ZDI) rewards them with a handsome amount. 

— Zero Day Initiative (@thezdi) March 21, 2019

Pwn2Own Roundup

The researchers who demonstrated new vulnerabilities in Oracle VirtualBox, Apple Safari and VMware workstation were awarded $240,000 on the first day of Pwn2Own 2019. Moving towards the second day, ZDI awarded an amount of $270,000 to those researchers who identified new bugs in Microsoft’s Edge and Mozilla Firefox browser.  This is how researchers managed to hack Edge: Most importantly, the kernel escalation flaw in Firefox 66 was demonstrated by Richard Zhu and Amat Cama officially known as Fluoroacetate received an award for $50,000. Niklas Baumstark used a sandbox escape technique to exploit Firefox 66.0 and received an award of $40,000.  All of these vulnerabilities have been reported to Microsoft and Mozilla, and the companies are working on the patches are expected to release in the next updates.  RELATED ARTICLES YOU NEED TO CHECK OUT:

Download Windows Defender Application Guard on Chrome and Firefox How to restore previous sessions in Microsoft Edge Firefox and Chrome can’t match Microsoft Edge security standards

Name * Email * Commenting as . Not you? Save information for future comments
Comment

Δ