Samsung Galaxy S26 Exposed in Multiple Security Breaches at Pwn2Own Ireland

www.news4hackers.com-samsung-galaxy-s26-exposed-in-multiple-security-breaches-at-pwn2own-ireland-samsung-galaxy-s26-exposed-in-multiple-security-breaches-at-pwn2own-ireland

On the second day of the Pwn2Own Ireland 2026 cybersecurity competition, researchers secured $232,500 in rewards by demonstrating 45 distinct zero-day vulnerabilities across multiple platforms.

Samsung Galaxy S26 Exploited Three Times at Pwn2Own Ireland 2026

The Samsung Galaxy S26 flagship device became a focal point as it was compromised three separate times by teams including KAIST Hacking Lab’s Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab’s Dimitrios Valsamaras and Ken Gannon.

Key Exploits and Rewards

Jack Dates of RET2 Systems showcased a Sonos Era 300 exploit chain that executed in under 60 seconds, while HaeJung Yang of the Out of Bounds team received $40,000 for breaching Dynamo in the AI Infrastructure category.

ZDI’s disclosure policy mandates that vendors have 90 days to address exploited vulnerabilities before details are publicly released.

Additional Exploits and Categories

Additional exploits targeting the Home Assistant Green smart home hub were achieved by PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec’s Yassine Bengana and Maxence Schmitt. Ikotas Labs also demonstrated a seven-stage zero-day attack against the Oracle Autonomous AI Database.

Competition Structure and Previous Achievements

The competition, organized by Trend Micro’s Zero Day Initiative (ZDI), focuses on identifying unpatched vulnerabilities in fully updated devices before they are weaponized in real-world attacks. All participating devices operate with the latest firmware versions, and competitors must achieve arbitrary code execution to validate their findings.

Event Categories and Targets

The second day featured seven categories of targets, including mobile devices (Samsung Galaxy S26 and Google Pixel 10), messaging applications, smart home systems, printers, AI infrastructure, AI coding tools, and a new wellness healthcare device category. Apple’s iPhone 17 was a high-value target with a $300,000 prize for a remote exploit, though no team attempted this challenge.

Historical Context and Past Successes

In the 2025 event, hackers demonstrated 73 zero-day flaws to earn $1,024,750, with Summoning Team securing $187,500 by exploiting the Samsung Galaxy S25, Home Assistant Green, QNAP TS-453E NAS, and multiple Synology devices.


Blog Image

About Author

en_USEnglish