Three independent research teams broke into a fully patched Google Pixel 10 during Pwn2Own Ireland 2026, the annual hacking contest held in Cork that pays researchers to demonstrate working exploits against production devices. Entrants are required to attack only bugs that have not already been disclosed to the vendor, and every winning Pixel 10 entry this year was a remote exploit — meaning the attacker had to compromise the phone through its default browser or over NFC, Wi-Fi, Bluetooth, or the baseband radio, with no physical access and no help from the owner.
What happened
Three of four scheduled attempts against the Pixel 10 succeeded; the fourth ran out of time on the contest's first day. The winning entries, in order:
- Team Xint (Tim Becker and Yves Bieri) used a single already-known bug — what the contest organizer, Trend Micro's Zero Day Initiative (ZDI), calls a "collision" — for a $150,000 award.
- Ikotas Labs chained multiple issues together for the full $300,000 top prize, even though its entry was also labeled a collision. ZDI has not explained why one partially-known entry was paid in full while the other was halved.
- Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara combined one known bug with one genuine zero-day for a $112,500 payout.
Ikotas Labs had the strongest showing of the event. Beyond the Pixel 10, the team also exploited a Samsung Galaxy S26 (every one of the seven attempts against the Galaxy S26 succeeded), OpenAI's Codex coding agent, and Oracle's Autonomous AI Database, bringing its total to $361,000 and the contest's "Master of Pwn" title.
ZDI's posted results don't describe exactly how any of the Pixel 10 exploits worked, and as of this writing the technical write-ups haven't been published. Google's own October Pixel security bulletin went out two days before the contest and makes no mention of these flaws, meaning there is currently no patch and no interim mitigation Pixel owners can apply for this specific set of bugs.
Beyond phones, researchers at the event also exploited Lexmark, Canon, and Brother printers; three smart-home devices (Sonos Era 300, Philips Hue Bridge Pro, and Home Assistant Green); and the Garmin Index BPM wellness tracker. Every product on the contest schedule was compromised at least once, and 51 of 63 scheduled attempts succeeded. Total payouts across the three days topped $1.2 million, up from roughly $1.02 million at last year's Ireland event.
Why it matters
A "fully patched, up-to-date flagship phone falls to a remote, zero-click-style exploit chain" is close to a worst case for mobile security teams: it shows that even a device with no known outstanding vulnerabilities can still be reached over the air, through nothing more than normal radio or browser exposure. Under Pwn2Own's rules, vendors now have 90 days to ship fixes before ZDI publishes full technical details — which also means these bugs will become public knowledge, and a template for attackers, well before most fleets have a confirmed patch.
The fact that six of the Galaxy S26's seven winning entries involved at least one previously-known-but-unpatched bug is a separate warning sign: it suggests vendor patch cycles are not always keeping pace with bugs that are already on record internally.
What to do
- Patch Pixel devices now against the known issue. Separately from the Pwn2Own results, Google patched a Pixel modem vulnerability, CVE-2026-58704, in September, warning it "may be under limited, targeted exploitation." Confirm affected devices are on patch level 2026-09-05 or later.
- Track the 90-day disclosure window. Security teams managing Pixel or Galaxy S26 fleets should watch Google's and Samsung's monthly bulletins closely over the coming months — a fix for the Pwn2Own-demonstrated bugs is likely to land as a dated security update rather than an emergency out-of-band patch.
- Reduce passive attack surface where you can. Since the winning entries relied on remote vectors — browser, NFC, Wi-Fi, Bluetooth, baseband — disabling radios that aren't in active use (NFC and Bluetooth in particular) reduces exposure on high-risk or high-value devices in the interim.
- Don't overlook adjacent IoT and peripheral devices. Printers, smart-home hubs, and wearables were all compromised at this event too; they deserve the same patch discipline and network segmentation as phones and laptops, not an exception from it.
