Google Pixel 10 Security Flaw: Pwn2Own Hackers Earn $560,000
Over $1.2 million in rewards were distributed at Pwn2Own Ireland 2026 for exploits targeting devices and systems, highlighting critical vulnerabilities in connected tech and AI infrastructure.
Event Overview
Pwn2Own Ireland 2026 concluded with participants securing over $1.2 million in rewards for demonstrating exploits against a range of devices and systems. The event emphasized vulnerabilities in smartphones, printers, smart speakers, smart home hubs, wellness devices, AI infrastructure, coding tools, and cloud databases.
Key Exploits and Rewards
Google Pixel 10 Exploits
The Google Pixel 10 emerged as a primary target, with three teams collectively earning more than $560,000 for their successful exploits. The Ikotas Labs team secured the maximum payout of $300,000 by combining multiple vulnerabilities to achieve remote access to a Pixel 10 device.
Tim Becker and Yves Bieri received $150,000 for their exploit, which utilized a previously disclosed flaw, limiting their reward. Dimitrios Valsamaras and Ken Gannon earned $112,500 for an exploit that combined a zero-day vulnerability with a known issue.
Previous Exploit Success
This marks the second time Valsamaras and Gannon have received compensation for mobile device exploits, having previously earned $50,000 for compromising a Samsung Galaxy S25. Their earlier work included demonstrations of vulnerabilities in Samsung’s Bixby virtual assistant.
Notable Vulnerabilities and Payouts
Other Significant Rewards
Notable payouts included $50,000 for a Sonos Era 300 smart speaker vulnerability. Additional rewards of $40,000 were distributed for exploits targeting Oracle’s Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, LiteLLM AI gateway, and Philips Hue Bridge Pro smart lighting system.
Researchers also received approximately $30,000 for vulnerabilities in the Samsung Galaxy S26 and Home Assistant Green smart home hub. Exploits targeting Lexmark and Brother printers, as well as the Garmin Index BPM blood pressure monitor, each earned $20,000.
Range of Vulnerabilities
Rewards for other vulnerabilities ranged from $4,250 to $17,500, covering devices such as the Sonos Era, Galaxy S26, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, Home Assistant Green, Chroma, Garmin Index BPM, and Canon imageFORCE 1643F.
Security Implications
All exploit details will be shared with affected vendors. No participants targeted the iPhone 17, which carried a maximum prize of $300,000. The event underscored ongoing challenges in securing connected devices and AI systems, with researchers highlighting the need for continuous vulnerability management and robust security frameworks.
Conclusion
Pwn2Own Ireland 2026 demonstrated the critical need for proactive security measures in an increasingly connected world. The event not only rewarded innovative exploit research but also emphasized the importance of collaboration between researchers and vendors to address emerging threats.
