// AI threat desk · 9 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesMediumPWN2OWNCVSS not assigned

Google Pixel 10 exploited at Pwn2Own Ireland 2026

Three Google Pixel 10 exploits earned more than $560,000, SecurityWeek reported. The Zero Day Initiative published the results on Oct 8, 2026.

AI-generated image of a security researcher testing a smartphone beside a laptop at a cybersecurity competition.
AI-generated image, not a photo of the event.
Key takeaways
  • Tim Becker and Yves Bieri remotely exploited Google Pixel 10 through a single bug collision and earned $150,000.
  • Ikotas Labs chained multiple issues to exploit Google Pixel 10 and earned $300,000.
  • The Zero Day Initiative recorded Team MAMMOTH using six zero-days against Home Assistant Green for $7,500.

Google Pixel 10 participants demonstrated successful remote exploits at Pwn2Own Ireland 2026, with the Zero Day Initiative publishing the results on Oct 8, 2026.

The three Pixel 10 demonstrations earned $150,000, $300,000 and $112,500. The contest also recorded successful remote exploitation of a Samsung Galaxy S26, while teams used multi-bug chains against Home Assistant Green and multifunction printers.

Pwn2Own is a computer hacking contest typically held with security conferences. The Zero Day Initiative said Day Three had 17 scheduled attempts, with roughly $1.33 million on the board.

On this page

Three teams demonstrated Google Pixel 10 exploit chains

The Zero Day Initiative recorded Tim Becker and Yves Bieri of Xint using a single bug collision for a successful remote Google Pixel 10 exploit. The result earned $150,000 and 15 Master of Pwn points.

Ikotas Labs chained multiple issues to exploit the phone, earning $300,000 and 30 Master of Pwn points. Dimitrios Valsamaras, Ken Gannon and others used a two-bug chain, including one collision and one zero-day, for $112,500 and 22.50 points.

SecurityWeek said the three teams collectively earned more than $560,000 for Google Pixel 10 exploits. It said Becker and Bieri did not receive the full payout because their exploit involved a previously known flaw, while the third Pixel demonstration combined a zero-day with a previously known vulnerability.

Pwn2Own teams targeted phones, smart-home devices and printers

The Zero Day Initiative recorded BunkyoWesterns using a two-bug chain against a Samsung Galaxy S26 for $8,250 and 3.75 Master of Pwn points.

Team MAMMOTH used six zero-days against Home Assistant Green for $7,500 and three Master of Pwn points. Team DDOS used a five-bug chain, including one zero-day, against the same product for $4,500.

Summoning Team used four unique bugs against a Canon imageFORCE 1643F Multifunction Copier for $5,000. FuzzingLabs used a single zero-day against a Brother MFC-L8970CDW for $20,000.

Pwn2Own payouts covered AI infrastructure and connected devices

SecurityWeek said participants earned more than $1.2 million for exploits targeting phones, printers, smart speakers, smart-home hubs, a wellness device, AI infrastructure, coding tools and cloud databases.

Cybernews reported that researchers said Pixel 10 may also be affected in connection with a Samsung Galaxy S26 Pwn2Own hack.

The affected vendors will be provided with the full details of all exploits, SecurityWeek said.

Google is working to improve Pixel phone security by focusing on the cellular baseband modem, which handles communication with mobile networks and processes external data, Help Net Security reported.

FAQ

What happened to Google Pixel 10 at Pwn2Own Ireland 2026?

SecurityWeek said participants demonstrated three Google Pixel 10 exploits that earned more than $560,000 collectively.

Who exploited Google Pixel 10 at Pwn2Own?

Tim Becker and Yves Bieri of Xint, Ikotas Labs, and a team involving Dimitrios Valsamaras, Ken Gannon and others were recorded as successful participants.

What other devices were exploited at Pwn2Own Ireland 2026?

Recorded targets included Samsung Galaxy S26, Home Assistant Green, Canon imageFORCE 1643F and Brother MFC-L8970CDW.

Will vendors receive details of the Pwn2Own exploits?

SecurityWeek said affected vendors will be provided with the full details of all exploits.

What did Google focus on to improve Pixel security?

Help Net Security reported that Google is focusing on the cellular baseband modem, which handles communication with mobile networks and processes external data.

Sources

  1. Zero Day Initiative, Pwn2Own Ireland 2026 - Day Three Results & Master of Pwn, Zero Day InitiativePrimary
  2. Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own, SecurityWeek
  3. Google makes it harder to exploit Pixel 10 modem firmware, Help Net Security
  4. Hackers crack Samsung Galaxy S26 and Pixel 10 with single email in zero-day attack, Cybernews
  5. Pwn2Own, Wikipedia
How we checked this story
ClaimSourceStatus
SecurityWeek reported that Pwn2Own Ireland 2026 participants earned more than $1.2 million for exploits targeting phones, printers, smart speakers, smart home hubs, a wellness device, AI infrastructure, coding tools, and cloud databases.SecurityWeekAttributed
SecurityWeek reported that three teams collectively earned more than $560,000 for Google Pixel 10 exploits.SecurityWeekAttributed
SecurityWeek reported that Ikotas Labs earned the full $300,000 payout by chaining multiple bugs to remotely hack a Pixel phone.SecurityWeekAttributed
SecurityWeek reported that Tim Becker and Yves Bieri received $150,000 for a Pixel exploit but did not receive the full payout because it involved a previously known flaw.SecurityWeekAttributed
SecurityWeek reported that Dimitrios Valsamaras and Ken Gannon earned $112,500 for a Pixel exploit chaining a zero-day with a previously known vulnerability.SecurityWeekAttributed
The Zero Day Initiative recorded a successful remote Google Pixel 10 exploit by Tim Becker and Yves Bieri that earned $150,000 and 15 Master of Pwn points.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded that Ikotas Labs chained multiple issues to exploit Google Pixel 10, earning $300,000 and 30 Master of Pwn points.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a Google Pixel 10 attack by Dimitrios Valsamaras, Ken Gannon, and others using a two-bug chain with one collision and one zero-day for $112,500.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a successful remote Samsung Galaxy S26 exploit by BunkyoWesterns using a two-bug chain for $8,250 and 3.75 Master of Pwn points.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a six-zero-day exploit against Home Assistant Green by Team MAMMOTH for $7,500 and three Master of Pwn points.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a five-bug chain including one zero-day against Home Assistant Green by Team DDOS for $4,500.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a four-bug chain against Canon imageFORCE 1643F that earned $5,000.Zero Day InitiativeConfirmed
The Zero Day Initiative recorded a single-zero-day exploit against Brother MFC-L8970CDW that earned $20,000.Zero Day InitiativeConfirmed
SecurityWeek reported that a researcher earned $50,000 for hacking a Sonos Era 300 smart speaker.SecurityWeekAttributed
SecurityWeek reported that $40,000 rewards were paid for exploits targeting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, and the LiteLLM AI gateway.SecurityWeekAttributed
The Zero Day Initiative said Day Three had 17 scheduled attempts with roughly $1.33 million on the board.Zero Day InitiativeConfirmed
SecurityWeek reported that vendors affected by the demonstrated exploits would receive the full exploit details.SecurityWeekAttributed
Help Net Security reported that Google is working to improve Pixel phone security by focusing on the cellular baseband modem.Google, via Help Net SecurityAttributed
Cybernews reported that researchers said Pixel 10 may also be affected in connection with a Samsung Galaxy S26 Pwn2Own hack.CybernewsAttributed
Wikipedia described Pwn2Own as a computer hacking contest typically held with security conferences.WikipediaConfirmed
zerodayinitiative.com published its report on Oct 8, 2026.zerodayinitiative.comConfirmed

Could not verify

  • Whether any demonstrated vulnerability was exploited in the wild is not established
  • Whether the Pixel 10 or Samsung Galaxy S26 exploits received CVE identifiers is not established
  • How many devices or users were affected is not established
  • Whether the separate Pwn2Own demonstrations exploited the same underlying vulnerabilities is not established
Explore with AI