• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Chinese hacker cracks Safari, wins $62.5K, praises Apple’s security

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
March 14, 2014, 4:07 PM ET

Keen Team’s Chen, right, demos an exploit to HP’s Joshua Smith

FORTUNE — Everybody’s Web software got “pwned” at the Pwn2Own hackers conference this week: Apple’s (AAPL) Safari, Google’s (GOOG) Chrome, Microsoft’s (MSFT) Internet Explorer, Mozilla’s Firefox and Adobe’s (ADBE) Reader and Flash.

Chrome was hacked by a French team from Vupen Security with a use-after-free vulnerability that affects both the WebKit and Blink rendering engines.

Safari was defeated by Liang Chen, one of a pair Chinese Keen Team hackers, using a heap-overflow-and-sandbox-bypass combination that took three months to perfect.

“For Apple, the OS is regarded as very safe and has a very good security architecture,” Chen told ThreatPost‘s Michael Mimoso. “Even if you have a vulnerability, it’s very difficult to exploit. Today we demonstrated that with some advanced technology, the system is still able to be pwned. But in general, the security in OS X is higher than other operating systems.”

In a separate interview with CNET, Chen said that OS X is harder to attack than iOS 7.0 because Apple issues security updates for its desktop operating system more frequently than for its mobile OS.

The two-day event, sponsored by Hewlett-Packard (HPQ) and organized by the HP-owned Zero-Day Initiative, paid out $850,000 in prize money to eight teams of competitors, plus another $82,500 in charitable donations. The event was staffed by observers from Apple and the other companies, which will presumably now start patching those holes.

“I think the Webkit fix will be relatively easy,” Chen told Mimoso. “The system-level vulnerability is related to how they designed the application; it may be more difficult for them.”

CORRECTION: An earlier version of this story had the prize money wrong. Keen Team won $62,500 for pwning Safari and another $75,000 for an Adobe Flash exploit for a total of $137,500. Source: Pwn2Own 2014: Rules and Unicorns 

About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Lists Calendar
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Lists Calendar
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Intel CEO Lip Bu Tan crushed Wall Street targets on his 1-year anniversary: We are embracing our ‘paranoid’ roots
Big TechIntel
Intel CEO Lip Bu Tan crushed Wall Street targets on his 1-year anniversary: We are embracing our ‘paranoid’ roots
By Alexei OreskovicApril 23, 2026
28 minutes ago
Feds charge U.S. Army soldier who made $400,000 from Polymarket bets tied to Maduro capture
LawPolymarket
Feds charge U.S. Army soldier who made $400,000 from Polymarket bets tied to Maduro capture
By Jeff John RobertsApril 23, 2026
4 hours ago
Zohran Mamdani
Personal FinanceTaxes
Ken Griffin’s Citadel fires back at NYC Mayor Zohran Mamdani ‘tax the rich’ video featuring his $238 million penthouse
By Catherina GioinoApril 23, 2026
4 hours ago
Should you pay off debt or save? How to decide
Personal Financemoney management
Should you pay off debt or save? How to decide
By Joseph HostetlerApril 23, 2026
5 hours ago
Jensen Huang stands smiling with his arms outstretched.
Big TechBillionaires
‘Don’t leave’: Jensen Huang challenges billionaire class as he insists ‘highest taxes in the world’ are OK with him
By Jacqueline MunisApril 23, 2026
5 hours ago
You can fly almost anywhere in Europe for €20 while Spirit Airlines is staving off bankruptcy. Here’s the difference
PoliticsAirline industry
You can fly almost anywhere in Europe for €20 while Spirit Airlines is staving off bankruptcy. Here’s the difference
By Catherina GioinoApril 23, 2026
5 hours ago

Most Popular

When interest on national debt overtook military spending, it triggered a limit where the U.S. may ‘cease to be a great power,’ warns Hoover historian
Economy
When interest on national debt overtook military spending, it triggered a limit where the U.S. may ‘cease to be a great power,’ warns Hoover historian
By Eleanor PringleApril 23, 2026
15 hours ago
Officials will flush 50,000 toilets to flood a Utah lake in order to generate electricity
Environment
Officials will flush 50,000 toilets to flood a Utah lake in order to generate electricity
By Mead Gruver, Dorany Pineda and The Associated PressApril 22, 2026
1 day ago
Cursor’s 25-year-old CEO is a former Google intern who just inked a $60 billion deal with SpaceX
AI
Cursor’s 25-year-old CEO is a former Google intern who just inked a $60 billion deal with SpaceX
By Marco Quiroz-GutierrezApril 22, 2026
1 day ago
Craving work-life balance is a huge red flag, says Fortune 500 Europe CEO—and like Barack Obama, he happily works through weekends
Success
Craving work-life balance is a huge red flag, says Fortune 500 Europe CEO—and like Barack Obama, he happily works through weekends
By Orianna Rosa RoyleApril 22, 2026
2 days ago
The Iran war is pushing Southeast Asia to debate the once unthinkable: Whether ships will need to pay to transit the Strait of Malacca
Economy
The Iran war is pushing Southeast Asia to debate the once unthinkable: Whether ships will need to pay to transit the Strait of Malacca
By Angelica AngApril 23, 2026
15 hours ago
Despite nearing their 60s, nearly four in 10 Americans heading towards the end of their careers don’t even have a retirement account
Success
Despite nearing their 60s, nearly four in 10 Americans heading towards the end of their careers don’t even have a retirement account
By Emma BurleighApril 23, 2026
11 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.