Pwn2Own Day 1 Sees Windows 11, Red Hat Linux, and VirtualBox Hacked

Pwn2Own Day 1 Sees Windows 11, Red Hat Linux, and VirtualBox Hacked

Hackers Break New Ground at Pwn2Own Berlin 2025: AI Falls, Big Targets Breached

Day one of Pwn2Own Berlin 2025 delivered high-stakes action and historic firsts. Security researchers executed 11 cutting-edge exploit attempts—including unprecedented attacks on AI systems—earning a total of $260,000 in rewards.

This year’s event shattered expectations with successful compromises of major platforms like Windows 11, Red Hat Linux, Oracle VirtualBox, and Docker Desktop. Making history, the AI category saw its first successful exploitation, signaling a major shift in the cybersecurity battleground.

Singapore’s STAR Labs pulled ahead early in the quest for the coveted Master of Pwn crown. But with more exploits yet to unfold, the competition remains fierce—and far from over.

Day One Detonates: Zero-Days Rip Through Key Platforms

The opening salvo of Pwn2Own Berlin 2025 left no doubt: critical systems are still vulnerable, and researchers are ready to prove it.

Among the standout moments, Red Hat Linux took two direct hits. Security researcher Pumpkin (@u1f383) of the DEVCORE Research Team cracked the system wide open using an integer overflow flaw to achieve local privilege escalation. The reward? $20,000 in prize money and two hard-earned points in the race toward Master of Pwn.

And that was just one of several precision strikes delivered on Day 1.

Precision Exploits & Strategic Strikes Define Day One

In a high-stakes play, Hyunwoo Kim (@V4bel) and Wongi Lee (@_qwerty_po) from Theori engineered a sophisticated exploit chain, blending an info leak with a use-after-free bug to gain root access. But a twist in the tale—a known N-day overlap—meant their payday was trimmed, landing them $15,000 and 1.5 points toward the Master of Pwn leaderboard.

Elsewhere, Windows 11 didn’t escape unscathed.

Chen Le Qi (@cplearns2h4ck) of STAR Labs SG delivered a textbook takedown. By fusing a use-after-free with an integer overflow, they escalated privileges all the way to SYSTEM. The result? A cool $30,000 prize and 3 Master of Pwn points, solidifying STAR Labs’ early dominance.

Flawless Hits and Final Blows: Windows 11 Under Siege

Marcin Wiązowski executed a surgical strike, landing a SYSTEM-level escalation through a pristine out-of-bounds write—no errors, no hiccups. The payout: $30,000 and a clean 3-point addition to his Master of Pwn tally.

Bringing the Windows 11 assault to a close, Hyeonjin Choi (@d4m0n_8) of Out Of Bounds unleashed a type confusion exploit that landed with precision. The reward: $15,000 and a full 3 points—cementing a fierce Day 1 finish.

Sandbox Shattered: VirtualBox and Docker Fall Hard

Team Prison Break (Best of the Best 13th) lived up to their name with a breakout performance—literally. By leveraging an integer overflow, they cracked Oracle VirtualBox wide open, escaping the guest environment and executing code directly on the host. The jailbreak earned them $40,000 and 4 crucial points on the Master of Pwn scoreboard.

But the day’s heaviest hit came courtesy of STAR Labs.

Billy and Ramdhan went deep into the Linux kernel, exploiting a use-after-free vulnerability to escape Docker Desktop’s container boundaries. Their precise execution delivered full code execution on the host system—and a commanding $60,000 payout, along with 6 points that shook up the rankings.


AI Joins the Battlefield – And It’s Already Bleeding

History was made as Sina Kheirkhah (@SinSinology) of the Summoning Team cracked Chroma, marking the first-ever AI system compromise in Pwn2Own history. The exploit, part of the debut AI category, earned $20,000 and 2 points—but more importantly, it fired a warning shot across the bow of the AI industry.

As artificial intelligence becomes foundational to our tech-driven future, today’s success sends a clear message: AI isn’t immune—it’s the new frontier.

Triton Turbulence: Collisions Cloud the AI Arena

NVIDIA’s Triton Inference Server became a flashpoint on Day 1—not for what it revealed, but for what it confirmed. Multiple teams hit known flaws, triggering collisions that reignited debate around disclosure timelines and vendor patch speed.

Sina Kheirkhah (@SinSinology) of Summoning Team and Viettel Cyber Security (@vcslab) each executed technically sound exploits, but with NVIDIA already aware of the vulnerabilities, the payout was reduced. Still, both walked away with $15,000 and 1.5 Master of Pwn points.

Wiz Research wasn’t as fortunate—their exploit faltered under pressure, missing the time window for a successful run.

With STAR Labs setting the pace atop the leaderboard, the spotlight now shifts to Day 2, where targets like Microsoft, AI frameworks, and other heavyweight platforms await scrutiny.

Beyond leaderboard drama, Triton’s collision-heavy showing exposed a critical truth: even disclosed vulnerabilities remain open doors if patches lag behind. And with AI now firmly on the hit list, a new cybersecurity battleground is coming into sharp focus.

More Articles & Posts