@Tim_G said in Edge the Big Loser at Pwn2Own:

The most impressive exploit by far, and also a first for Pwn2Own, was a virtual machine escape through an Edge flaw by a security team from “360 Security.” The team leveraged a heap overflow bug in Edge, a type confusion in the Windows kernel, and an uninitialized buffer in VMware Workstation for a complete virtual machine escape.
The team hacked its way in via the Edge browser, through the guest Windows OS, through the VM, all the way to the host operating system. This impressive chained-exploit gained the 360 Security team $105,000.

I thought VMWare fixed the possibility of this from being possible? This is now the third time I've heard of VM escape on the VMWare platform.

I wonder who is tracking VM escape rates.