Cybersecurity

Galaxy S26 Hacked Three Times on the Second Day of Pwn2Own Ireland

Cybersecurity researchers collected $232,500 after exploiting 45 zero-day vulnerabilities on the second day of Pwn2Own Ireland 2026, including three successful attacks on the Samsung Galaxy S26. The competition includes devices, phones, and artificial intelligence infrastructure platforms.

2026-10-08
3 min read
0 views
certi.news Editorial Team
Galaxy S26 Hacked Three Times on the Second Day of Pwn2Own Ireland

The second day of the Pwn2Own Ireland 2026 competition saw the exploitation of 45 zero-day vulnerabilities, enabling researchers to collect cash prizes totaling $232,500. The day’s highlight was the Samsung Galaxy S26 being hacked three times by Kyeongmin Kim from KAIST Hacking Lab, the PetoWorks team, and Dimitrios Valsamaras and Ken Gannon from Mobile Hacking Lab.

Jack Dates of RET2 Systems also demonstrated an exploit chain targeting the Sonos Era 300 speaker in less than a minute. The Out of Bounds team, represented by HaeJung Yang, received a $40,000 prize after hacking the Dynamo platform in the artificial intelligence infrastructure category.

Other Targets Hacked

PetoWorks and Yves Bieri of Xint, along with Kyeongmin Kim and McCaulay, as well as Yassine Bengana and Maxence Schmitt of Doyensec, managed to hack the Home Assistant Green smart home hub. The Ikotas Labs team also hacked the Oracle Autonomous AI Database using a chain consisting of seven zero-day vulnerabilities.

Before the day’s events began, Kyeongmin Kim withdrew his attempt to target the Google Pixel 10 through a USB-based attack. The Samsung Galaxy S26 and Google Pixel 10 were among the targets in the mobile category, while no researcher attempted to target the iPhone 17, despite the maximum prize for a remote attack being set at $300,000.

Why Does This Matter?

Pwn2Own tests are conducted on devices running the latest firmware versions, and participants are required to hack the target and demonstrate the ability to execute arbitrary code. Therefore, the repeated hacking of the Galaxy S26 is not merely a technical showcase; it demonstrates that updated devices may remain vulnerable to complex exploit chains before fixes become available.

Trend Micro Zero Day Initiative organizes the competition to discover vulnerabilities before they are exploited in real-world attacks. After vulnerabilities are disclosed during the competition, manufacturers are given 90 days to release patches before ZDI publishes the details publicly. The report does not specify whether Samsung has issued fixes for these vulnerabilities or whether all the exploits were based on entirely new vulnerabilities; it noted that some vulnerabilities used in the first day’s hacks were already known to the company.

Competition Context

The 2026 edition includes seven categories, including mobile phones, messaging applications, smart home devices, printers, artificial intelligence infrastructure, and artificial intelligence programming applications, in addition to a new category targeting healthcare and wellness devices.

On the first day, teams from Interrupt Labs and Ikotas Labs, along with Nguyen Thanh Dat of Viettel Cyber Security, also hacked the Galaxy S26. Vũ Chí Thành and Huỳnh Đức Tin of VinSOC also received $40,000 for a chain of five zero-day vulnerabilities targeting the Oracle Autonomous AI Database, and an additional $40,000 for a chain of seven vulnerabilities against the Philips Hue Bridge Pro. Attempts to hack smart home devices, artificial intelligence platforms, and printers, along with the Galaxy S26 and Google Pixel 10, are scheduled to continue on the third day.

For comparison, the Pwn2Own Ireland 2025 competition featured 73 zero-day vulnerabilities, and total prizes reached $1,024,750.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news