OS X And Safari First Casualty At Pwn2Own Hacking Contest

Devin Coldewey

Devin Coldewey is a Seattle-based writer and photographer. He has written for the TechCrunch network since 2007. Some posts he’d like you to read: The Dangers of Externalizing Knowledge | Generation i | Surveillant Society | Choose Two | Frame Wars | The User’s Manifesto | Our Great Sin His personal website is coldewey.cc. → Learn More

Wednesday, March 9th, 2011

The annual “Pwn2Own” contest has just kicked off at CanSecWest, and Apple was the first to fall. A fully-patched Snow Leopard machine running Safari was made to launch an application (Calculator) and write a file, just from visiting a specific web page. It didn’t even crash the browser!

The exploit is in Webkit, meaning it could potentially apply to iOS browsers as well, though that has yet to be demonstrated. And to be fair, most of the other browser/OS combos will get taken down over the next couple days as well.