Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

Three teams break into a fully patched Pixel 10 remotely at Pwn2Own Ireland

Three research teams broke into a fully patched Google Pixel 10 remotely at Pwn2Own Ireland on October 8, collecting $562,500 between them. Google has 90 days to ship fixes before the technical details go public, and Pixel owners have no patch or workaround to apply until then.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Three teams break into a fully patched Pixel 10 remotely at Pwn2Own Ireland
Photo: thehackernews.com

What happened

  • At least two of the three Pixel 10 wins used a bug that someone already knew about before the attempt.
  • Ikotas Labs' Pixel 10 exploit took the contest's $300,000 top prize and made the team the overall winner.
  • All three entries were registered as remote, meaning entry through web content in the default browser or over NFC, Wi-Fi, Bluetooth or baseband.
  • Samsung's Galaxy S26 was exploited in all seven attempts made on it, and six of those seven wins included at least one collision.
  • Google's October Pixel bulletin came out on October 6, two days before the demonstrations, and does not mention the contest.

Why it matters

  • exposure For at least two of the Pixel flaws, someone besides the winning team knew of the bug before October 8, so the exposure started before the contest and lasts until Google ships a fix.
  • decision Fleet owners have nothing to deploy for the contest bugs, so the Pixel patch decision open today is confirming phones sit at 2026-09-05 or later, the level that fixes CVE-2026-58704.
  • contradiction ZDI's rules pay collisions less, yet Ikotas Labs drew the full prize under a collision label, so ZDI's own results conflict on whether its Pixel bug was already known.

Under the contest rules, a win means code of the attacker's choice running on the phone, or sensitive information pulled off it [11]. All three Pixel 10 teams met that bar [1][11]. As of October 9, ZDI had posted the results but not how any of the exploits work, and the route each team used had not been published [4][11]. The wins were demonstrations on contest phones [5]. Pwn2Own pays for working exploits and passes the flaws to the vendors [2]. Three of the four remote attempts on the Pixel 10 succeeded. The fourth, on the first day, ran out of time [12].

The rules ask for bugs that neither the vendor nor ZDI already knows about. ZDI calls an entry that relies on a previously known bug a collision, and such an entry may still be accepted for a reduced award [6]. So a collision means the flaw had at least two finders before October 8: the contestant and whoever reported it first [25]. For one Galaxy S26 bug, ZDI said who that was. A bug in the chain Ikotas Labs used on the first day "was already known to the vendor (yet unpatched)," ZDI said [16].

Every Pixel entry was competing for the same listed prize of $300,000 and 30 points [7]. Xint went first and was paid $150,000 and 15 points, half the listed amounts, according to ZDI's posted results [8]. Take Xint's $150,000 and Ikotas Labs' $300,000 out of the $562,500 total and $112,500 is left for the third win [7][9][23].

The 90-day figure comes from a June article by TrendAI, Trend Micro's enterprise security business [13]. Under that process, vendors get 90 days to release patches before ZDI publishes the full technical details [13]. Counted from October 8, the window ends on January 6, 2027 [24]. Neither Google's bulletin nor ZDI's results give a date for a Pixel fix or announce a release outside Google's bulletins [14].

Only one Pixel flaw in this story carries an exploitation warning from Google, and it has nothing to do with the contest. In September Google patched a Pixel modem flaw, CVE-2026-58704, that it said "may be under limited, targeted exploitation" [21].

Across the three days, 51 of the 63 scheduled attempts succeeded, and every product on the schedule was exploited at least once [18]. Ikotas Labs also won on OpenAI's Codex coding agent and Oracle's Autonomous AI Database, finishing with $361,000 and 42.5 points across four wins [17]. ZDI's posted awards topped $1.2 million, up from $1,024,750 at last year's Ireland contest [20]. No attempt was scheduled on Apple's iPhone 17 or on WhatsApp, though each carried a $300,000 top prize [19].

What to watch

  • Google's November and December Pixel bulletins, and whether either credits fixes to the Pwn2Own Ireland Pixel 10 entries.
  • ZDI advisories for the three Pixel 10 entries, which would show whether each team came in through the browser or over NFC, Wi-Fi, Bluetooth or baseband.
  • Any Google note that one of the contest bugs is under exploitation, the warning it attached to CVE-2026-58704 in September.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched.

    ReportedSupportedView cited source
  2. [2]

    The contest pays researchers to show working exploits and passes the flaws to the vendors.

    ReportedSupportedView cited source
  3. [3]

    One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 9, 2026

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories