Fully patched Google Pixel 10 smartphones were remotely compromised three times at Pwn2Own Ireland 2026, with competing research teams earning roughly $560,000 in prize money and underscoring how high-end mobile devices remain vulnerable even when up to date.[3][14][15] The Cork-based contest paid out about $1.2 million overall for successful exploits against phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools, highlighting a broad attack surface for modern connected environments.[8][9][14]
The Pixel 10 category required contestants to break into the device remotely, either through malicious web content opened in the default browser or via NFC, Wi-Fi, Bluetooth or baseband radio links, and all attempts were run against fully patched phones.[3][8][15] One winning exploit chain from Ikotas Labs earned a top prize of $300,000 and enough points to secure the Master of Pwn title, while Xint researchers took home $150,000 and a team led by Dimitrios Valsamaras received $112,500 for their respective Pixel compromises.[2][3][5] Together, the three successful entries demonstrated that attackers can chain multiple bugs to reliably bypass Android’s layered defenses on a flagship device.[3][15]
Technical details of the Pixel 10 exploit chains are being kept under wraps for now, in line with Pwn2Own rules that prioritize coordinated disclosure and vendor patching.[3][15] Trend Micro’s Zero Day Initiative (ZDI), which runs the contest, has published only high-level descriptions and prize tables so far, noting that some of the Pixel entries involved “bug collisions,” where researchers reused vulnerabilities that were already known but combined them with new flaws to achieve remote compromise.[3][5][15] As of October 9, ZDI had not disclosed specific vulnerability primitives, and public CVE identifiers and CVSS severity scores for the underlying bugs were still pending, leaving defenders to plan ahead without full exploit details.[3][15]
The Pixel hacks were part of a larger Pwn2Own Ireland campaign that saw 98 zero-day vulnerabilities demonstrated and approximately $1.262 million awarded across multiple categories, including other smartphones such as Samsung’s Galaxy S26, networked printers, smart lighting, audio gear and AI-related services.[2][11][14] That breadth of successful exploitation against consumer and enterprise-grade hardware shows that attackers are steadily expanding beyond traditional desktop and server targets, probing everything from home automation gear to AI coding assistants for gaps in default configurations and vendor hardening.[8][11][14]
For defenders, the fact that multiple teams remotely compromised fully patched Pixel 10 handsets should serve as a warning that routine monthly updates alone are not sufficient to eliminate high-impact mobile risks.[3][15] The contest rules and results make clear that the browser, Wi-Fi, Bluetooth, NFC and baseband stacks remain attractive and viable vectors, even on devices that benefit from Google’s latest security features and mitigations.[3][8][15] Once Google issues fixes, organizations will need to prioritize those updates for Pixel fleets and other Android devices that may share vulnerable components through common libraries or chipset firmware.
Until more concrete vulnerability information and patches are available, security teams should tighten mobile attack surfaces by enforcing mobile device management policies, limiting risky wireless features where feasible, and monitoring for suspicious browsing and network activity that could indicate exploitation attempts. Paying close attention to upcoming Android security bulletins and vendor advisories, and rapidly deploying related updates to high-value users and frontline staff, will be critical steps in turning the lessons of Pwn2Own Ireland 2026 into material risk reduction for real-world environments.
References
- Pwn2Own Ireland chiude con 98 zero-day e 1,26 milioni di premi
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
- Pwn2Own Ireland Researchers Exploit 32 Zero-Days … – Mallory.ai
- Actualité cybersécurité — Veille quotidienne | FactualRisk
- LATEST
- Pwn2Own Ireland 2026 day one: 32 zero-days and US$388,500 awarded, with exploits against the Samsung Galaxy S26, Oracle Autonomous AI Database, OpenAI Codex, LiteLLM, Philips Hue Bridge Pro, Sonos Era 300, Lexmark printers and a Garmin blood pressure monitor
- Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
- Vulnerability — Latest News, Reports & Analysis
