Back to Newsroom
Threat Intel

Samsung Galaxy S26 Hacked Again as Pwn2Own Ireland Zero-Days Pile Up

On day two of Pwn2Own Ireland 2026, researchers cracked Samsung's Galaxy S26 flagship three more times, breached an AI database through a seven-exploit chain, and compromised a popular smart home hub — collecting $232,500 in bounties along the way.

Samsung Galaxy S26 Hacked Again as Pwn2Own Ireland Zero-Days Pile Up

Day two of Pwn2Own Ireland 2026 delivered another wave of bad news for device makers, with security researchers walking away with $232,500 in bounties after exploiting 45 unique zero-day vulnerabilities across phones, smart home gear, and AI systems.

What happened

Samsung's brand-new Galaxy S26 was the day's headline target, compromised three separate times by independent teams using distinct exploit chains. A Sonos speaker was broken into in under a minute. A home automation hub was hacked by multiple competing teams using different techniques, and one team chained together seven separate zero-day flaws to break into an AI-powered database platform. A planned attack on Google's Pixel 10 was withdrawn before it could be attempted.

Pwn2Own is organized by Trend Micro's Zero Day Initiative, which invites researchers to find and demonstrate zero-day exploits against fully patched, up-to-date devices. Vendors are given 90 days to ship a fix before details are made public — a window intended to balance public disclosure with responsible patching.

This year's contest spans seven categories: mobile phones, messaging apps, smart home devices, printers, AI infrastructure, AI coding tools, and — new for 2026 — wellness and healthcare devices. Apple's iPhone 17 was also on the target list, with a bounty of up to $300,000 for a remote compromise, but no team attempted it.

Why it matters

Across just two days, researchers have already disclosed more than 70 previously unknown vulnerabilities in mainstream consumer and enterprise products — flagship smartphones, AI-powered databases, and the smart home devices increasingly sitting on home and business networks. The sheer range of categories broken — from a speaker to an AI database to a brand-new flagship phone — underlines how exploit chains increasingly combine several individually "minor" bugs into a complete, working compromise. AI infrastructure in particular is proving to be fertile ground: both an AI-driven database and an AI coding-agent target were among the systems breached.

For organizations, the takeaway isn't that any single product is uniquely weak — it's that the attack surface of connected devices, AI platforms, and mobile hardware is large and interconnected, and that "fully patched" alone is no guarantee of safety against a determined, resourced attacker.

What to do

  • Patch promptly once vendors ship fixes tied to this event — Pwn2Own's 90-day disclosure window means updates will land over the coming months.
  • Inventory and monitor smart home and IoT devices on your network the same way you would any other endpoint; several of this year's targets are off-the-shelf consumer products already deployed widely.
  • Apply extra scrutiny to AI infrastructure and AI-assisted coding tools in your environment — this year's results show these systems are now a serious research and attack focus, not just a theoretical risk.
  • If you manage mobile fleets, track Samsung and Google security bulletins closely over the next quarter; both the Galaxy S26 and Pixel 10 were contest targets.
SHARE