Skip to main content
CybersecurityHacking

Security Researchers Exploit 32 Zero-Days at Pwn2Own Ireland

Security research lab setup with devices and equipment, including Samsung, Apple, and Google phones.

$388,500 was paid out after researchers exploited 32 zero‑day flaws on the first day of Pwn2Own Ireland 2026.

What happened on day one: high pay, many bugs

On the opening day of Pwn2Own Ireland 2026, competing security researchers exploited 32 zero‑day vulnerabilities and collected $388,500 in awards. The competition targeted products across seven categories: mobile phones (the Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new wellness healthcare devices category.

Samsung Galaxy S26: multiple teams, mixed novelty

Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security successfully hacked the Samsung Galaxy S26 flagship during day one. The event report notes that some of the bugs used in those challenges were already known to the vendor, even as the teams still earned payouts for their demonstrations.

Printers, Sonos, LiteLLM and OpenAI Codex: a broad front of exploits

Researchers demonstrated a range of successful attacks beyond mobile phones. The Lexmark CX532adwe and the Canon imageFORCE 1643F multifunction printers were both hacked during day one. Security teams exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker again. In the AI and coding arms of the contest, testers demoed zero‑days against LiteLLM and brought down the OpenAI Codex cloud‑based AI coding agent with a single argument‑injection bug.

Near‑misses and time constraints: the Google Pixel 10 effort

Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Google Pixel 10 on day one but were unable to complete an exploit within the allotted time. The schedule keeps the Pixel 10 and Samsung Galaxy S26 on the agenda: day two again lists the Galaxy S26 and Pixel 10 in the mobile phones category, and day three will include further attempts against those flagships alongside additional smart home, AI infrastructure, and printer targets.

Zero Day Initiative rules and the disclosure clock

The Zero Day Initiative (ZDI) organizes Pwn2Own to identify zero‑day vulnerabilities in targeted devices before threat actors can exploit them. After a flaw is exploited at Pwn2Own, vendors receive 90 days to release security updates before Trend Micro's ZDI publicly discloses the vulnerabilities. That disclosure timeline was reiterated in the event material for the 2026 contest.

What this means for technologists, vendors, and end users

  • Technologists and security teams: tools and infrastructure that were targeted — printers (Lexmark CX532adwe, Canon imageFORCE 1643F), smart speakers (Sonos Era 300), AI systems (LiteLLM, OpenAI Codex), and flagship phones (Samsung Galaxy S26, Google Pixel 10) — will remain focal points for validation and patch testing as vendors respond under the 90‑day disclosure rule.
  • Vendors and product owners: the contest highlighted that some exploits used known bugs already in vendor queues; vendors face a 90‑day window to ship fixes before public disclosure by ZDI, a specific deadline that will shape patch prioritization.
  • End users and procurement leaders: devices and services shown to be exploitable at Pwn2Own — including the Galaxy S26, Pixel 10 attempts, multifunction printers, Sonos speakers, and cloud AI coding agents — are the exact items to watch for vendor advisories and updates.

Last year’s Pwn2Own Ireland results remain part of the contest’s context: in 2025 researchers earned $1,024,750 for 73 zero‑day flaws, and Summoning Team collected $187,500 after exploiting a string of targets that included the Samsung Galaxy S25 and several NAS and smart‑home products.

Organizers are also offering a two‑hour digital summit featuring Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian on the topic of “what AI‑speed attacks change,” how defenders should adapt, and how to validate and fix at machine speed.

The first day’s tally — 32 zero‑days and nearly $390,000 in payouts — underlines the contest’s stated purpose: to surface practical, demonstrable vulnerabilities across mobile, home, enterprise, and AI stacks and to put a firm timeline on vendor remediation before public disclosure.

Read the original BleepingComputer story