Pwn2Own Ireland 2026: researchers exploit 32 zero-days, hack Galaxy S26 twice
On the opening day of Pwn2Own Ireland 2026, security researchers chained 32 zero-day vulnerabilities to breach devices across categories including mobile phones, printers, smart home gadgets and AI systems, earning $388,500 in prizes. Samsung's Galaxy S26 was compromised twice, while VinSOC researchers led the leaderboard after chaining seven zero-days against a Philips Hue Bridge Pro and five against Oracle's Autonomous AI Database. Other targets included OpenAI's Codex coding agent, Lexmark and Canon printers, a Sonos Era 300 speaker, and LiteLLM, though an attempt on the Google Pixel 10 failed within the time limit.
GoKawiil's interpretation of the reporting above, not reported fact.
The scale of exploitation across phones, printers, AI tools and smart-home hubs suggests these product categories still harbor significant unpatched attack surfaces despite vendor hardening efforts. Because Trend Micro's Zero Day Initiative gives vendors 90 days to patch before public disclosure, affected companies like Samsung, Oracle, OpenAI, Lexmark, Canon and Sonos now face pressure to ship fixes quickly. The contest's expansion into AI infrastructure and coding agents also signals growing researcher attention toward AI systems as a new frontier for security flaws.
- 32 zero-day exploits were used on day one, earning competitors $388,500.
- Samsung's Galaxy S26 was successfully hacked twice; the Google Pixel 10 exploit failed.
- VinSOC topped the leaderboard with chained exploits against Philips Hue and Oracle's AI Database.
Source: bleepingcomputer.com, 2026-10-06
Published there as: “Hackers exploit 32 zero-days on first day of Pwn2Own Ireland”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.