Ethical Hacking News
At the Pwn2Own Ireland event, three teams successfully demonstrated remote hacks of fully patched Google Pixel 10 devices, earning top prizes and demonstrating vulnerabilities in the devices. The contest aimed to pay researchers $300,000 for showing working exploits and passing the bugs to the vendors. The top prize was earned by Ikotas Labs, which made the team the overall winner, while Samsung's Galaxy S26 was exploited in all seven attempts made on it during the contest. The results highlight the ongoing vulnerability of devices despite being fully patched.
Three research teams successfully demonstrated remote hacks of fully patched Google Pixel 10 devices in a recent Pwn2Own Ireland event. The top prize of $300,000 was earned by Ikotas Labs, which made the team the overall winner. The contest rules require every target to be fully patched, and researchers who find bugs are paid $300,000 for showing working exploits and passing the bugs to the vendors. Three Pixel 10 entries were registered as remote exploits, and all three attempts succeeded except one, which ran out of time. Ikotas Labs' exploit was labeled as a "collision" in the results, which means it used an already-known bug, but still earned the full prize of $300,000. Other products on the schedule were also exploited, including Samsung's Galaxy S26, Lexmark and Canon printers, smart home devices, and a wellness device. The total prize money awarded in the contest was over $1.2 million, with Ikotas Labs earning $361,000 and Apple's iPhone 17 missing from the schedule.
A recent Pwn2Own Ireland event, a hacking contest, saw three research teams successfully demonstrate remote hacks of fully patched Google Pixel 10 devices. The contest, which requires every target to be fully patched, aims to pay researchers $300,000 for showing working exploits and passing the bugs to the vendors. The top prize was earned by Ikotas Labs, which made the team the overall winner. Trend Micro's Zero Day Initiative (ZDI) posted the results but had not published how the three exploits work as of October 9.
The contest rules require each entry to use bugs that are not already known to the vendor or to the organizer. An entry that uses an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize. The three Pixel 10 wins, in the order they happened, were: ZDI's Description, Award, Points. The team Xint used "a single bug collision" and earned $150,000 and 15 points. The Ikotas Labs team used "chained multiple issues together" and earned $300,000 and 30 points. The Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara team used a chain of two bugs: one collision and one zero-day and earned $112,500 and 22.5 points.
Together, the three wins paid $562,500. All three teams were competing for the same listed prize of $300,000 and 30 points. Xint went first, and its win was first announced with the full prize still to be confirmed, then set at $150,000 and 15 points, half the listed amounts. Ikotas Labs went second and received the full $300,000 and 30 points. Its entry is also labeled a collision in the results, with no explanation of the label or of why the full prize was paid.
All three Pixel 10 entries were registered as remote exploits. Under the rules, that means breaking into the phone through web content opened in its default browser or over one of four radio links: NFC, Wi-Fi, Bluetooth or baseband. A winning entry must run code of the attacker's choice on the phone or pull sensitive information from it. Which route each team used, and what each exploit did on the phone, has not been published.
Three of the four remote attempts on the Pixel 10 succeeded. The other, on the contest's first day, ran out of time. The contest rules require winning teams hand their exploits and write-ups to ZDI, and the bugs are passed to the affected vendors. Vendors then have 90 days to release patches before ZDI publishes the full technical details, according to a June article from TrendAI, Trend Micro's enterprise security business.
Google's October Pixel bulletin was published on October 6, two days before the Pixel 10 exploits were shown, and does not mention the contest. ZDI's results list no fix and no step for Pixel owners to take. The Galaxy S26 and Other Results saw Samsung's Galaxy S26 was exploited in all seven attempts made on it during the contest. Six of the seven winning entries included at least one collision. ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on the first day "was already known to the vendor (yet unpatched)" at the time.
Ikotas Labs also exploited OpenAI's Codex coding agent and, on the second day, Oracle's Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI's posted results. ZDI named it Master of Pwn, the title for the contestant with the most points. Researchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.
Every product on the schedule was exploited at least once, and 51 of the 63 scheduled attempts succeeded. The schedule listed no attempt on Apple's iPhone 17 or on WhatsApp, each with a top prize of $300,000. ZDI's posted awards for the three days add up to more than $1.2 million, above the $1,024,750 it awarded at last year's Ireland contest. Separately, Google in September patched a Pixel modem flaw, CVE-2026-58704, that it said "may be under limited, targeted exploitation." Pixel phones at patch level 2026-09-05 or later have that fix.
Related Information:
https://www.ethicalhackingnews.com/articles/Three-Teams-Demonstrate-Remote-Hacks-of-Fully-Patched-Google-Pixel-10-at-Pwn2Own-ehn.shtml
https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html
Published: Fri Oct 9 06:12:35 2026 by llama3.2 3B Q4_K_M