Pwn2Own Ireland 2026: Samsung Galaxy S26 Hacked Three Times on Day One
The Samsung Galaxy S26 did not last long at Pwn2Own Ireland 2026, as it was hacked three times on the very first day of the competition. Here’s what you need to know.
The Pwn2Own Ireland 2026 hacking competition opened on October 6, 2026, in Cork, Ireland. Organized by the Zero Day Initiative, it includes more than 60 exploit attempts over three days, including 21 on the first day alone. And smartphones are clearly in demand: "We’ve never had so many attempts on phones", Dustin Childs notes in the full schedule published by the ZDI.
Researchers must demonstrate a working exploit against a fully patched target within a limited time, and the vulnerabilities are then handed over to the vendors so they can be fixed. Last May, I covered this topic during the Berlin edition, which ended with 47 zero-day vulnerabilities discovered. This time, the spotlight is more consumer-focused, with smartphones, printers and connected devices, as well as AI tools.
Samsung Galaxy S26: 3 exploit chains
The first day wrapped up with 28 zero-day vulnerabilities, and some of them affected the Samsung Galaxy S26. Each attempt can earn participants up to $50,000 and 5 Master of Pwn points. But no team secured the maximum payout because the exploit chains combined a new flaw with already known exploits. Specifically:
- Viettel Cyber Security: Nguyen Thanh Dat chained four vulnerabilities, three of which were already known to Samsung. The team earned $31,250.
- Interrupt Labs: four bugs as well, including three collisions and only one zero-day, for $15,750.
- Ikotas Labs: four vulnerabilities, including one already known to Samsung but still unpatched. The team pocketed $11,000.
In Pwn2Own terminology, a collision refers to a security issue already known to the vendor or to a previous participant. But known does not mean fixed: targets are normally running the latest version of the system, with all available patches applied. So if a known flaw still works on an up-to-date Galaxy S26, the patch has not yet been deployed.
And this may not be over for the Galaxy S26 yet! The program still includes four more attempts against this model before the competition ends. Google’s Pixel 10 is also in the crosshairs, with up to $300,000 on the line if a team manages a remote compromise.
Sonos, LiteLLM and Philips Hue also targeted
Beyond smartphones, hacker teams also demonstrated exploits in other tools and products:
- Sonos Era 300: McCaulay Hudson combined an out-of-bounds write with another flaw.
- LiteLLM: Taisic Yun of Xint obtained a reverse shell thanks to an input validation flaw coupled with code injection.
- Philips Hue Bridge Pro: the VinSOC team chained seven zero-day vulnerabilities.
- Lexmark CX532adwe: Team Confused only needed a single use-after-free to compromise the printer.
Now we are waiting for the patches: vendors have 90 days to release a fix before the ZDI discloses the technical details. That said, there are still 2 days left in the competition, so more zero-day vulnerabilities are likely to be identified.
If you’d like, follow the event on this page.


