
Security researchers successfully exploited Google’s Pixel 10 three times on the third and final day of Pwn2Own Ireland 2026, earning a combined $562,500 and helping Ikotas Labs secure the Master of Pwn title.
The competition concluded with $1,262,000 awarded for 98 unique zero-day vulnerabilities, according to the final leaderboard, which recorded 61 completed attempts across 29 research teams.
The third and last session also brought successful demonstrations against Samsung’s Galaxy S26, smart home controllers, printers, and Oracle’s Autonomous AI Database, extending the findings from the previous two days.
Organized by TrendAI’s Zero Day Initiative (ZDI) in Cork, the contest rewards researchers for demonstrating exploits against designated targets and disclosing the vulnerabilities to affected vendors. This year’s categories included mobile phones, messaging apps, smart home products, printers, wellness devices, AI infrastructure, and coding agents.

ZDI
Pixel exploits decide the winner
Tim Becker and Yves Bieri of Xint delivered the day’s first successful remote exploit against the Pixel 10. Their entry used a single vulnerability classified as a collision, earning $150,000 and 15 Master of Pwn points.
A collision means the vendor or organizers already knew about the vulnerability, potentially through an earlier contestant’s disclosure, and it can reduce an otherwise successful entry’s reward.
Ikotas Labs subsequently compromised the Pixel 10 by chaining multiple issues, collecting $300,000 and 30 points. ZDI marked the result as a success with a collision but did not provide a detailed breakdown of the vulnerabilities involved.
That award propelled Ikotas Labs to first place, finishing with $361,000, 42.5 points, and 13 unique bugs. Xint placed second with $240,000 and 27.5 points, followed by Team ZyGoat with $125,000 and the same points total.
The third Pixel demonstration came from Dimitrios Valsamaras and Ken Gannon using Djini.ai from Mobile Hacking Lab, and Tenia Valsamara of CENSUS Labs. Their remote exploit combined one zero-day with one collision, earning $112,500 and 22.5 points.
BunkyoWesterns also remotely exploited Samsung’s Galaxy S26 using one unique vulnerability and one collision, receiving $8,250 and 3.75 points.
Smart homes, databases, and printers hacked
Team MAMMOTH closed the competition with a six-zero-day chain against Home Assistant Green, earning $7,500 and three points. Team DDOS separately compromised the same controller with a five-bug chain containing one zero-day, collecting $4,500.
Summoning Team and McCaulay each earned $5,000 for Philips Hue Bridge Pro exploits built entirely from collisions.
Oracle’s Autonomous AI Database fell to OtterSec and Platform Security. Each team’s chain contained one unique vulnerability alongside multiple collisions, earning $6,250 and $6,000, respectively.
In the printer category, FuzzingLabs researchers Lucas Van Haaren and Hugo Leclercq earned $20,000 for a single zero-day in the Brother MFC-L8970CDW. Summoning Team collected $5,000 for four unique bugs in the Canon imageFORCE 1643F, while Cong Thanh, Duc Hieu, and Nam Dung received $5,000 for two unique vulnerabilities in the Lexmark CX532adwe.
White Noise Club’s attempt against the Garmin Index BPM was unsuccessful within the allotted time.
Under the contest rules, successful researchers provide ZDI with exploit details for disclosure to the affected vendors. Users should monitor the relevant security advisories and install software and firmware updates as fixes become available in the coming weeks.







Leave a Reply