Elite hackers wrapped up Pwn2Own Berlin 2025 with a dramatic finale, breaching Windows 11, VMware ESXi, and Mozilla Firefox through freshly uncovered zero-day flaws. Their advanced exploits secured $383,750 in prizes on the third and final day alone.
Over the course of the three-day competition, researchers exposed 28 never-before-seen vulnerabilities, pushing the total payout to an unprecedented $1,078,750—a new milestone in Pwn2Own history.

Windows 11 Breaches Push Privilege Boundaries
Pwn2Own Berlin’s final day spotlighted serious privilege escalation flaws in Windows 11. The DEVCORE Research Team’s Angelboy showcased a dual-bug chain to elevate access, though Microsoft had previously flagged one of the vulnerabilities. Even with that overlap, the high-impact demo secured a $11,250 reward.
Capping off the Windows exploits, Milos Ivanovic used a precise time-of-check to time-of-use (TOCTOU) race condition to reach SYSTEM-level privileges. His method, which manipulates the fleeting window between a condition check and its usage, netted him $15,000 for its novelty and effectiveness.
VMware’s Virtual Walls Breached
Virtualization defenses took a major hit, with VMware products facing two standout attacks:
- Corentin BAYET (Reverse Tactics) delivered a powerful double-hit on VMware ESXi. His exploit blended an integer overflow with an uninitialized variable flaw, illustrating how even partially known vulnerabilities can be leveraged in new ways. Despite some overlap with prior reports, the impact earned him $112,500.
- Thomas Bouzerar and Etienne Helluy-Lafont (Synacktiv) went after VMware Workstation, unleashing a heap-based buffer overflow attack. By writing data beyond allocated memory, they opened the door to arbitrary code execution — and walked away with $80,000 in prize money.
Firefox Compromised by JavaScript Flaw
Renowned security researcher Manfred Paul, a past “Master of Pwn” titleholder, cracked open Firefox’s renderer using an integer overflow in the JavaScript engine. Now designated CVE-2025-4919, this vulnerability enabled out-of-bounds memory access and posed a potential RCE (Remote Code Execution) threat. Mozilla awarded Paul $50,000 for his discovery — and quickly issued a patch, underscoring the real-time value of these competitions.
AI Infrastructure Under Fire
Demonstrating that AI platforms are no safe haven, Wiz Research targeted the NVIDIA Container Toolkit with an attack exploiting External Initialization of Trusted Variables. Their findings highlighted security gaps in AI deployment layers and brought in $30,000 in winnings.
Multi-Layered Attack on VirtualBox and Windows
Bringing together virtualization and OS-level abuse, Dung and Nguyen (STARLabs) pulled off a chained exploit on Oracle VirtualBox and Windows. They first escaped the VM using a TOCTOU condition, then escalated privileges through a separate array index validation flaw. The intricate two-stage attack earned them $70,000.
STARLabs SG Crowned “Master of Pwn”
With standout performances across multiple categories, STARLabs SG dominated the leaderboard, securing the “Master of Pwn” title with $320,000 in total earnings and 35 competition points.
Looking Ahead: Patching the Fallout
All vulnerabilities unearthed at Pwn2Own have been responsibly disclosed to vendors. They now have a 90-day window to issue patches before full public disclosure. Mozilla has already acted, reinforcing the critical role live exploit contests play in improving software security across the ecosystem.




