SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
Three teams break into a fully patched Pixel 10 remotely at Pwn2Own Ireland
Three research teams broke into a fully patched Google Pixel 10 remotely at Pwn2Own Ireland on October 8, collecting $562,500 between them. Google has 90 days to ship fixes before the technical details go public, and Pixel owners have no patch or workaround to apply until then.
The Watch · Security desk

What happened
- At least two of the three Pixel 10 wins used a bug that someone already knew about before the attempt.
- Ikotas Labs' Pixel 10 exploit took the contest's $300,000 top prize and made the team the overall winner.
- All three entries were registered as remote, meaning entry through web content in the default browser or over NFC, Wi-Fi, Bluetooth or baseband.
- Samsung's Galaxy S26 was exploited in all seven attempts made on it, and six of those seven wins included at least one collision.
- Google's October Pixel bulletin came out on October 6, two days before the demonstrations, and does not mention the contest.
Why it matters
- exposure For at least two of the Pixel flaws, someone besides the winning team knew of the bug before October 8, so the exposure started before the contest and lasts until Google ships a fix.
- decision Fleet owners have nothing to deploy for the contest bugs, so the Pixel patch decision open today is confirming phones sit at 2026-09-05 or later, the level that fixes CVE-2026-58704.
- contradiction ZDI's rules pay collisions less, yet Ikotas Labs drew the full prize under a collision label, so ZDI's own results conflict on whether its Pixel bug was already known.
Under the contest rules, a win means code of the attacker's choice running on the phone, or sensitive information pulled off it [11]. All three Pixel 10 teams met that bar [1][11]. As of October 9, ZDI had posted the results but not how any of the exploits work, and the route each team used had not been published [4][11]. The wins were demonstrations on contest phones [5]. Pwn2Own pays for working exploits and passes the flaws to the vendors [2]. Three of the four remote attempts on the Pixel 10 succeeded. The fourth, on the first day, ran out of time [12].
The rules ask for bugs that neither the vendor nor ZDI already knows about. ZDI calls an entry that relies on a previously known bug a collision, and such an entry may still be accepted for a reduced award [6]. So a collision means the flaw had at least two finders before October 8: the contestant and whoever reported it first [25]. For one Galaxy S26 bug, ZDI said who that was. A bug in the chain Ikotas Labs used on the first day "was already known to the vendor (yet unpatched)," ZDI said [16].
Every Pixel entry was competing for the same listed prize of $300,000 and 30 points [7]. Xint went first and was paid $150,000 and 15 points, half the listed amounts, according to ZDI's posted results [8]. Take Xint's $150,000 and Ikotas Labs' $300,000 out of the $562,500 total and $112,500 is left for the third win [7][9][23].
The 90-day figure comes from a June article by TrendAI, Trend Micro's enterprise security business [13]. Under that process, vendors get 90 days to release patches before ZDI publishes the full technical details [13]. Counted from October 8, the window ends on January 6, 2027 [24]. Neither Google's bulletin nor ZDI's results give a date for a Pixel fix or announce a release outside Google's bulletins [14].
Only one Pixel flaw in this story carries an exploitation warning from Google, and it has nothing to do with the contest. In September Google patched a Pixel modem flaw, CVE-2026-58704, that it said "may be under limited, targeted exploitation" [21].
Across the three days, 51 of the 63 scheduled attempts succeeded, and every product on the schedule was exploited at least once [18]. Ikotas Labs also won on OpenAI's Codex coding agent and Oracle's Autonomous AI Database, finishing with $361,000 and 42.5 points across four wins [17]. ZDI's posted awards topped $1.2 million, up from $1,024,750 at last year's Ireland contest [20]. No attempt was scheduled on Apple's iPhone 17 or on WhatsApp, though each carried a $300,000 top prize [19].
What to watch
- Google's November and December Pixel bulletins, and whether either credits fixes to the Pwn2Own Ireland Pixel 10 entries.
- ZDI advisories for the three Pixel 10 entries, which would show whether each team came in through the browser or over NFC, Wi-Fi, Bluetooth or baseband.
- Any Google note that one of the contest bugs is under exploitation, the warning it attached to CVE-2026-58704 in September.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched.
- [2]
The contest pays researchers to show working exploits and passes the flaws to the vendors.
- [3]
One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner.
- [4]
Trend Micro's Zero Day Initiative (ZDI), which runs Pwn2Own, posted the results but had not published how the three exploits work as of October 9.
- [5]
The wins were demonstrations on contest phones, and at least two of the three used a bug that was already known before the attempt.
- [6]
Contest rules require each entry to use bugs not already known to the vendor or the organizer; an entry using an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize.
- [7]
Together, the three Pixel 10 wins paid $562,500. All three teams were competing for the same listed prize of $300,000 and 30 points.
- [8]
Xint went first; its win was set at $150,000 and 15 points, half the listed amounts.
- [9]
Ikotas Labs went second and received the full $300,000 and 30 points; its entry is also labeled a collision in the results, with no explanation of the label or of why the full prize was paid.
- [10]
All three Pixel 10 entries were registered as remote exploits, meaning breaking into the phone through web content opened in its default browser or over NFC, Wi-Fi, Bluetooth or baseband.
- [11]
A winning entry must run code of the attacker's choice on the phone or pull sensitive information from it; which route each team used and what each exploit did has not been published.
- [12]
Three of the four remote attempts on the Pixel 10 succeeded; the other, on the contest's first day, ran out of time.
- [13]
Winning teams hand their exploits and write-ups to ZDI and the bugs are passed to vendors, who then have 90 days to release patches before ZDI publishes full technical details, according to a June article from TrendAI, Trend Micro's enterprise security business.
- [14]
Google's October Pixel bulletin was published on October 6, two days before the Pixel 10 exploits were shown, and does not mention the contest; ZDI's results list no fix and no step for Pixel owners to take.
- [15]
Samsung's Galaxy S26 was exploited in all seven attempts made on it; six of the seven winning entries included at least one collision.
- [16]
ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on the first day "was already known to the vendor (yet unpatched)" at the time.
- [17]
Ikotas Labs also exploited OpenAI's Codex coding agent and Oracle's Autonomous AI Database; its four wins add up to $361,000 and 42.5 points, and ZDI named it Master of Pwn.
- [18]
Every product on the schedule was exploited at least once, and 51 of the 63 scheduled attempts succeeded.
- [19]
The schedule listed no attempt on Apple's iPhone 17 or on WhatsApp, each with a top prize of $300,000.
- [20]
ZDI's posted awards for the three days add up to more than $1.2 million, above the $1,024,750 awarded at last year's Ireland contest.
- [21]
Google in September patched a Pixel modem flaw, CVE-2026-58704, that it said "may be under limited, targeted exploitation."
- [22]
Pixel phones at patch level 2026-09-05 or later have the CVE-2026-58704 fix.
- [23]
The third Pixel 10 win was paid $112,500.
- [24]
A 90-day window counted from October 8, 2026 ends on January 6, 2027.
- [25]
Each Pixel bug that counted as a collision had at least two finders before October 8: the contestant and the earlier party that made it known to the vendor or to ZDI.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comThree Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vulnerability DisclosureFollow
- Hacking competitionsFollow
- Mobile securityFollow