Skip to main content
CybersecurityHacking

Samsung Galaxy S26 Exploited Three Times at Pwn2Own Ireland

Sleek smartphone on a podium in a bright, cybersecurity event setting.

On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.

Samsung Galaxy S26: three successful exploits on day two

The Samsung Galaxy S26 flagship was a repeated focal point for contestants on day two, with three distinct successful compromises. KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon each demonstrated exploits that met Pwn2Own's requirement to show arbitrary code execution. The event rules require targets to run the latest firmware, and contestants must demonstrate full compromise to collect awards.

High-value targets breached: Oracle Autonomous AI Database, Home Assistant Green, Dynamo

Beyond mobile phones, researchers demonstrated significant chain-based attacks against broader infrastructure and smart-home equipment. Ikotas Labs used a seven-chain zero-day exploit to breach the Oracle Autonomous AI Database. VinSOC's Vũ Chí Thành and Huỳnh Đức Tin — who topped the leaderboard on day one — were awarded $40,000 for a five-zero-day exploit chain targeting the same Oracle Autonomous AI Database and another $40,000 for chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub.

Home Assistant Green was another repeat target. PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt all succeeded in hacking the Home Assistant Green smart home hub. In the AI infrastructure category, Out of Bounds team's HaeJung Yang received $40,000 for hacking Dynamo.

Notable demos and speed: Sonos Era 300 and USB attempt withdrawal

Several rapid or technically complex demonstrations stood out. Jack Dates of RET2 Systems demoed an exploit chain against a Sonos Era 300 in under a minute. Before day two began, Kyeongmin Kim withdrew an attempt at a USB-based attack that had targeted the Google Pixel 10; the Pixel 10 remained on the list of mobile targets for the contest.

On day one, Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security also demonstrated exploits against the Galaxy S26, although the source notes some of the bugs used on day one were already known to the vendor.

Rules, disclosure timelines, and contest scope

The competition is organized by Trend Micro's Zero Day Initiative (ZDI) to identify zero-day flaws in fully patched devices before they are exploited in the wild. Pwn2Own rules stipulate that all devices run the latest firmware versions and that contestants must compromise the target and demonstrate arbitrary code execution to be eligible for awards. After vulnerabilities are exploited and disclosed at Pwn2Own, vendors are given 90 days to patch their software before ZDI publicly discloses the details.

Contestants at Pwn2Own Ireland 2026 are targeting products across seven categories: mobile phones (explicitly the Samsung Galaxy S26 and the Google Pixel 10), messaging apps, smart home devices, printers, AI infrastructure, AI coding apps, and a newly introduced category for wellness healthcare devices. The event also listed Apple's iPhone 17 as a potential target with a maximum award of $300,000 for a remote hack, but no contestant registered an attempt on that device.

What this means for technologists, vendors, and end users

  • Technologists and security teams: Expect additional disclosure-driven remediation work tied to the 90-day timeline — particularly for repeated targets such as the Samsung Galaxy S26 and Oracle Autonomous AI Database, both of which were compromised multiple times during the event.
  • Vendors and procurement leaders: Devices demonstrated at Pwn2Own — including smart-home hubs like Home Assistant Green and Philips Hue Bridge Pro, AI infrastructure such as Oracle Autonomous AI Database, and consumer hardware like the Galaxy S26 — are now highlighted for prioritized review and potential patching under the ZDI disclosure cadence.
  • End users and operators: The contest underscores that fully patched devices can still be vulnerable to chaining multiple zero-days. Users of the named products should watch for vendor advisories and patches that will follow the event's coordinated disclosure process.

The contest moves into its third day with researchers set to attempt additional compromises of smart home, AI infrastructure, and printer devices — and with both the Samsung Galaxy S26 and Google Pixel 10 slated for further attempts. As Pwn2Own Ireland proceeds, the combination of cash awards, public demonstrations, and the 90-day disclosure clock will keep pressure on vendors to convert these public proofs into fixes.

https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/