The opening day of Pwn2Own Ireland 2026 delivered a stark reminder of the relentless pressure on flagship smartphone security, as researchers demonstrated three separate exploit chains against Samsung’s Galaxy S26. Hosted in Cork, Ireland, on October 6, the competition — organized by TrendAI’s Zero Day Initiative (ZDI) — saw more than 60 entries across a crowded three-day schedule, with a record number of mobile phone attempts. By day’s end, 28 zero-day vulnerabilities had been disclosed, earning contestants a combined $342,500, though several payouts were reduced because exploit chains included previously known bugs.
Pwn2Own is one of the most closely watched events in the vulnerability research calendar. It rewards security teams for publicly demonstrating working exploits against fully patched, in-market devices and software. The underlying vulnerabilities are then disclosed to the affected vendors, giving them a window to develop fixes before the details become public. This year’s categories span mobile phones, smart home devices, wellness products, printers, messaging platforms, AI infrastructure, and coding agents — reflecting the expanding attack surface of modern technology.
The Galaxy S26 attempts underscore how even a heavily scrutinized device can be compromised through a blend of old and new weaknesses.
Three independent teams breach Samsung’s Galaxy S26
The Galaxy S26, Samsung’s latest flagship, was targeted repeatedly on day one, and each attempt succeeded. The outcomes highlight both the sophistication of modern exploit chains and the complexity of defending a single device against multiple attack vectors.
Nguyen Thanh Dat of Viettel Cyber Security was the first to crack the device, exploiting it with a chain of four bugs. Three of these were already known to Samsung — classed as “collisions” under contest rules — but one was a new zero-day. The combination earned $31,250 and 3.25 Master of Pwn points.
Interrupt Labs followed, also using four bugs. Their chain included three collisions and one zero-day, netting $15,750 and 3.25 points. A third team, Ikotas Labs, combined four bugs as well, one of which was known to the vendor but remained unpatched. They received $11,000 and 4.5 points.
Under Pwn2Own rules, previously known vulnerabilities can still qualify for reduced awards at the organizer’s discretion. A collision does not necessarily indicate that a flaw has been fixed; targets generally run the latest fully patched operating system available, unless a category specifies otherwise. The Galaxy S26 attempts underscore how even a heavily scrutinized device can be compromised through a blend of old and new weaknesses.
What is a collision in Pwn2Own? A featured snippet answer
A collision occurs when a researcher submits an exploit that includes a vulnerability already known to the vendor — either because it was independently discovered, previously disclosed, or patched in part. While collisions reduce the payout, they still demonstrate that the device is vulnerable and that existing mitigations may be insufficient. The organizer retains discretion over whether the exploit qualifies for a reduced award, often based on the severity and the extent to which the known bug was leveraged.
Broader day-one results: Sonos, LiteLLM, Philips Hue, and Lexmark
Beyond the Galaxy S26, several other high-profile targets fell on the opening day. The Sonos Era 300 smart speaker was breached by McCaulay Hudson, who combined an out-of-bounds write with a format-string vulnerability to earn $50,000 and five Master of Pwn points. VinSOC’s linhlhq and Son Dinh also succeeded against the same Sonos model, using a two-bug chain that contained one publicly known flaw, earning $17,500 and 3.5 points.
In the AI infrastructure category, Xint’s Taisic Yun obtained a reverse shell on LiteLLM — an open-source proxy for large language models — through improper input validation and code injection. That exploit earned $40,000 and four points. Separately, Out of Bounds researchers HaeJung Yang and ByungYoung Yi used four bugs against LiteLLM, two previously known, for $15,000 and three points.
Other confirmed wins included VinSOC’s seven-zero-day exploit against the Philips Hue Bridge Pro, worth $40,000, and Team Confused’s single use-after-free vulnerability in the Lexmark CX532adwe printer, worth $20,000.
What does Pwn2Own mean for everyday users?
The immediate consequence of these demonstrations is a wave of vulnerability disclosures to affected vendors like Samsung, Sonos, Signify (Philips Hue), LiteLLM maintainers, and Lexmark. Each successful entry must be accompanied by detailed exploit documentation, which ZDI then shares privately with the manufacturer. Users and administrators should monitor for subsequent security advisories and apply relevant updates as soon as they become available.
The event also serves as a stress test for the security posture of devices that millions of people rely on daily. The fact that a flagship smartphone less than a year old can be compromised three times in a single day, using combinations of known and unknown flaws, underscores the gap between vendor patching cycles and real-world attack capability. It also reinforces the value of bug bounty programs and competitive research events in driving vendor responsiveness.
Context and significance for the security industry
Pwn2Own has been running for over a decade, but the Irish edition — launched in 2022 — has become a key venue for mobile and IoT security research. The 2026 edition extends the scope to AI infrastructure and coding agents, reflecting the industry’s pivot toward generative AI tools. The inclusion of targets like OpenAI Codex and Oracle Autonomous AI Database signals that the contest is adapting to the priorities of both attackers and defenders.
The record number of phone entries this year — including the Galaxy S26 and Google Pixel 10 — indicates that mobile devices remain a primary focus for researchers. With mobile operating systems becoming increasingly locked down, successful chains often require multiple steps: exploiting a browser, escalating privileges through kernel bugs, and bypassing hardware-based mitigations. The fact that teams achieved this three times against the same model suggests that Android’s security model, while robust, still leaves room for multi-stage attacks.
For Samsung, the three Galaxy S26 hacks are a mixed signal. On one hand, the company benefits from early disclosure of vulnerabilities that could otherwise be sold on the gray market. On the other, the repeated demonstrations erode the narrative that modern flagship phones are effectively impenetrable. The presence of known-but-unpatched flaws in two of the three chains also raises questions about the speed and thoroughness of Samsung’s patch deployment.
As Pwn2Own Ireland 2026 continues into its second and third days, additional targets are expected to fall. Participants will vie not only for prize money but also for the prestigious Master of Pwn title, awarded to the researcher or team that accumulates the most points across the event. The early leaderboard is already shifting, with significant points awarded for the Sonos and Galaxy S26 exploits.
For security teams and technology buyers alike, the lesson is clear: no device is unhackable, and the battle between offensive researchers and defensive engineers produces a steady stream of improvements that ultimately benefit everyone. The exploits demonstrated in Cork this week will soon be patched, but the cycle will repeat at the next Pwn2Own, pushing the boundaries of what attackers can achieve and what defenders must prepare for.