Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

MediumBleepingComputer · Sergiu Gatlan·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
Samsung
Reported by
1 outlet

On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.

The day's highlight was the Samsung Galaxy S26 flagship getting hacked three times by KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon.

Jack Dates of RET2 Systems demoed a Sonos Era 300 exploit chain in under a minute, and Out of Bounds team's HaeJung Yang was awarded $40,000 for hacking Dynamo in the AI Infrastructure category.

PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt also hacked the Home Assistant Green smart home hub, while Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.

Before day two began, Kyeongmin Kim withdrew his attempt at a USB-based attack targeting the Google Pixel 10.

Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws in fully patched devices before attackers exploit them in the wild. According to Pwn2Own rules, all devices run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution.

After zero-days are exploited and disclosed at Pwn2Own, vendors have 90 days to patch their software before ZDI publicly discloses them.

Throughout the Pwn2Own Ireland 2026 contest, competitors target products in seven categories, including mobile phones (Samsung Galaxy S26 and Google Pixel 10), messaging apps, smart home devices, printers, AI infrastructure, AI coding apps, and a new category where hackers will try to exploit wellness healthcare devices.

While Apple's iPhone 17 was also a potential target with a maximum award of $300,000 for a remote hack, no contestant registered for an attempt.

Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security also hacked Samsung's Galaxy S26 flagship on day one, but some of the bugs exploited were already known to the vendor.

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC, who topped the leaderboard on the first day, won $40,000 for a five-zero-day exploit chain targeting the Oracle Autonomous AI Database, plus an additional $40,000 for chaining seven zero-daysto exploit a Philips Hue Bridge Pro smart lighting hub.

On the third day, security researchers will attempt to hack multiple smart home, AI infrastructure, and printer devices, as well as the Samsung Galaxy S26 and Google Pixel 10 smartphones again.

During the Pwn2Own Ireland 2025 competition, hackers demoed 73 zero-day flaws to earn $1,024,750. Summoning Team won the contest and collected $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS, and multiple Synology devices.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Originally published by BleepingComputer. © BleepingComputer. Written by Sergiu Gatlan.

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. BleepingComputer ↗Established SourceFirst reported

    2026-10-08 06:32 UTC

Related stories