Swati KhandelwalOct 09, 2026Vulnerability / Mobile Security
Three research teams broke into Google’s Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest’s top prize, and made the team the overall winner.
Trend Micro’s Zero Day Initiative (ZDI), which runs Pwn2Own, posted the results but had not published how the three exploits work as of October 9. The wins were demonstrations on contest phones, and at least two of the three used a bug that was already known before the attempt.
The contest rules require each entry to use bugs that are not already known to the vendor or to the organizer. An entry that uses an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize.
The three Pixel 10 wins, in the order they happened:
| Team | ZDI’s Description | Award | Points |
|---|---|---|---|
| Xint (Tim Becker and Yves Bieri) | Used “a single bug collision” | $150,000 | 15 |
| Ikotas Labs | “chained multiple issues together” (entry labeled a collision) | $300,000 | 30 |
| Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara | A chain of two bugs: one collision and one zero-day | $112,500 | 22.5 |
Together, the three wins paid $562,500. All three teams were competing for the same listed prize of $300,000 and 30 points.
Xint went first. Its win was first announced with the full prize still to be confirmed, then set at $150,000 and 15 points, half the listed amounts.
Ikotas Labs went second and received the full $300,000 and 30 points. Its entry is also labeled a collision in the results, with no explanation of the label or of why the full prize was paid.
All three Pixel 10 entries were registered as remote exploits. Under the rules, that means breaking into the phone through web content opened in its default browser or over one of four radio links: NFC, Wi-Fi, Bluetooth or baseband.
A winning entry must run code of the attacker’s choice on the phone or pull sensitive information from it. Which route each team used, and what each exploit did on the phone, has not been published.
Three of the four remote attempts on the Pixel 10 succeeded. The other, on the contest’s first day, ran out of time.
What Happens Next
Under the rules, winning teams hand their exploits and write-ups to ZDI, and the bugs are passed to the affected vendors. Vendors then have 90 days to release patches before ZDI publishes the full technical details, according to a June article from TrendAI, Trend Micro’s enterprise security business.
Google’s October Pixel bulletin was published on October 6, two days before the Pixel 10 exploits were shown, and does not mention the contest. ZDI’s results list no fix and no step for Pixel owners to take.
Galaxy S26 and Other Results
Samsung’s Galaxy S26 was exploited in all seven attempts made on it during the contest. Six of the seven winning entries included at least one collision. ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on the first day “was already known to the vendor (yet unpatched)” at the time.
Ikotas Labs also exploited OpenAI’s Codex coding agent and, on the second day, Oracle’s Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI’s posted results. ZDI named it Master of Pwn, the title for the contestant with the most points.
Researchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.
Every product on the schedule was exploited at least once, and 51 of the 63 scheduled attempts succeeded. The schedule listed no attempt on Apple’s iPhone 17 or on WhatsApp, each with a top prize of $300,000.
ZDI’s posted awards for the three days add up to more than $1.2 million, above the $1,024,750 it awarded at last year’s Ireland contest.
Separately, Google in September patched a Pixel modem flaw, CVE-2026-58704, that it said : “may be under limited, targeted exploitation.” Pixel phones at patch level 2026-09-05 or later have that fix.


