Microsoft Edge, Windows 11, and LiteLLM Hacked at Pwn2Own Berlin 2026

Top ethical hackers wasted no time breaking into modern software and AI platforms at Pwn2Own Berlin 2026, exposing critical zero-day vulnerabilities across Microsoft Edge, Windows 11, LiteLLM, and NVIDIA technologies.

On the first day alone, researchers demonstrated 24 unique zero-day exploits and earned a total of $523,000 in rewards, according to Trend Micro’s Zero Day Initiative (ZDI).

The event highlighted how rapidly expanding attack surfaces, especially in AI systems, are creating new security risks for enterprises and developers.

Microsoft Edge Sandbox Escape

One of the most significant exploits came from DEVCORE researcher Orange Tsai, who chained four logic flaws to escape the Microsoft Edge sandbox.

Microsoft Edge Exploited (Source: Zero Day Initiative)
Microsoft Edge Exploited (Source: Zero Day Initiative)

This sandbox is designed to isolate browser processes and prevent malicious code from affecting the system.

By bypassing this protection, the exploit enabled code execution outside the restricted environment, potentially leading to full system compromise.

The attack earned $175,000, making it the highest payout of the day. Sandbox escape vulnerabilities are particularly dangerous because they defeat a core browser security boundary.

Windows 11 Privilege Escalation Attacks

Windows 11 was another major target, with multiple successful privilege escalation exploits demonstrated:

  • DEVCORE used an improper access control flaw to gain elevated privileges
  • Marcin Wiązowski exploited a heap-based buffer overflow
  • Kentaro Kawane chained two use-after-free vulnerabilities
Another Windows 11 Exploited (Source: Zero day Initiative)
Another Windows 11 Exploited (Source: Zero day Initiative)

These flaws allow attackers to move from standard user access to administrative control, a critical step in many real-world cyberattacks. Such vulnerabilities can enable lateral movement, persistence, and full takeover of systems.

AI Platforms Under Attack

AI tools emerged as a key focus area during the competition. Researcher k3vg3n successfully chained three vulnerabilities, including SSRF and code injection, to compromise LiteLLM, a platform used to manage large language model APIs.

The exploit showed how attackers could abuse AI infrastructure to execute unauthorized commands or access internal services. Similarly, STARLabs SG chained five bugs to exploit LM Studio, demonstrating how complex AI workflows can introduce multiple weak points.

Compass Security also exploited OpenAI Codex using a CWE-150 flaw, highlighting risks in AI coding assistants that are increasingly integrated into development pipelines.

NVIDIA and Linux Exploits

NVIDIA technologies were also successfully targeted. Researchers exploited the NV Container Toolkit using a single bug, while NVIDIA Megatron Bridge was compromised through path traversal and weak access control issues.

In addition, IBM X-Force demonstrated a race condition vulnerability to escalate privileges on Red Hat Enterprise Linux systems, reinforcing that traditional infrastructure remains a high-value target.

exploit NVIDIA Megatron Bridge in the second round (Source: Zero day Initiative)
 exploit NVIDIA Megatron Bridge in the second round (Source: Zero day Initiative)

Not all exploit attempts succeeded. Some attacks against OpenAI Codex and Oracle Autonomous AI Database failed or were classified as “collisions,” meaning the vulnerabilities were already known to vendors.

This year’s Pwn2Own clearly shows a shift toward AI-focused targets, including AI databases, coding agents, and local inference systems.

The findings suggest that while AI technologies are advancing, their security maturity is still evolving.

As the competition continues, more vulnerabilities are expected to emerge, offering critical insights into how attackers may target next-generation software, operating systems, and AI-driven platforms.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories