"may be under limited, targeted exploitation," Google said.
Pwn2Own Ireland: Three teams break into the fully patched Pixel 10 on October 8
Three research teams demonstrated remote compromises of Google's Pixel 10 at Pwn2Own Ireland on October 8, a contest that requires every target to be fully patched. Trend Micro's Zero Day Initiative (ZDI), which runs Pwn2Own, posted the results but had not published technical details of how the three Pixel exploits worked as of October 9. The demonstrations were performed on contest phones; at least two of the three entries used a bug that was already known before the attempts.
The three Pixel 10 wins, in the order they occurred, together paid $562,500. All three teams were competing for the same listed prize of $300,000 and 30 points. Xint went first and was initially announced with the full prize still to be confirmed; its award was later set at $150,000 and 15 points, half the listed amounts. Ikotas Labs went second and received the full $300,000 and 30 points; ZDI's results nevertheless label that entry a collision without publishing an explanation for the label or why the full prize was paid.
All three Pixel 10 entries were registered as remote exploits. Under the contest rules, that means breaking into the phone through web content opened in its default browser or over one of four radio links: NFC, Wi‑Fi, Bluetooth or baseband. A winning entry must run code of the attacker's choice on the phone or pull sensitive information; ZDI had not published which route each team used or what each exploit did on the phone. Three of the four remote attempts on the Pixel 10 succeeded; the other, on the contest's first day, ran out of time.
ZDI rules, collisions, and the 90‑day disclosure timeline
ZDI's Pwn2Own rules require each entry to use bugs that are not already known to the vendor or to ZDI. An entry that uses an already‑known bug — which ZDI calls a collision — can still be accepted at a lower prize. Under the contest process, winning teams hand their exploits and write‑ups to ZDI, and ZDI passes the bugs to the affected vendors. Vendors then have 90 days to release patches before ZDI publishes the full technical details, according to a June article from TrendAI, Trend Micro's enterprise security business.
At the time ZDI posted the contest results, it had not published the exploit write‑ups for the Pixel 10 wins and listed no fix or step for Pixel owners to take. Google had published its October Pixel bulletin on October 6, two days before the Pwn2Own demonstrations, and that bulletin does not mention the contest.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildIkotas Labs and Xint: awards, collisions, and the Master of Pwn
Ikotas Labs emerged as the highest earner at Pwn2Own Ireland. Its entry against the Pixel 10 earned $300,000 and 30 points and is labeled a collision in the posted results. Ikotas also exploited OpenAI's Codex coding agent and, on the second day of the contest, Oracle's Autonomous AI Database. Across the event Ikotas's four wins added up to $361,000 and 42.5 points, earning the team ZDI's title of Master of Pwn.
Xint's Pixel 10 win was registered first but ultimately received half the listed prize — $150,000 and 15 points. ZDI's published results note collisions in multiple winning chains across the event; in one instance ZDI said a bug used in a Galaxy S26 chain "was already known to the vendor (yet unpatched)" at the time.
Galaxy S26, printers, smart home gear and wearables: the wider haul
The contest schedule listed a broad slate of targets and nearly all were exploited. Samsung's Galaxy S26 was exploited in all seven attempts made on it during the contest; six of the seven winning entries included at least one collision. Researchers also produced successful exploits against Lexmark, Canon and Brother printers; three smart home devices — Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green — and the Garmin Index BPM wellness device.
Every product on the schedule was exploited at least once, and 51 of the 63 scheduled attempts succeeded. The schedule listed no attempt on Apple's iPhone 17 or on WhatsApp, each of which had a top prize of $300,000. ZDI's posted awards for the three days add up to more than $1.2 million, an increase from the $1,024,750 it awarded at last year's Ireland contest.
Pixel owners, Google and the near term
Two items matter for Pixel owners based on the record ZDI published. First, Google published a Pixel bulletin on October 6 that does not reference the contest demonstrations shown October 8. Second, ZDI's contest results list no fix and offer no step for Pixel owners to take. Separately, Google patched a Pixel modem flaw in September (CVE‑2026‑58704) and said that flaw "may be under limited, targeted exploitation;" Pixel phones at patch level 2026‑09‑05 or later contain that fix.
By the contest's own disclosure process, ZDI will pass exploit write‑ups to vendors and vendors will have up to 90 days to publish patches before ZDI releases full technical details. Until those write‑ups and vendor patches appear in the public record, ZDI's posted results are the clearest official account available of which devices were broken and what prizes were paid.
Original story: Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own



