Samsung Galaxy S26 hacked three times on day two of Pwn2Own Ireland
Security researchers collected $232,500 on day two of Pwn2Own Ireland 2026, with the Samsung Galaxy S26 hacked three separate times.

Security researchers collected $232,500 on day two of Pwn2Own Ireland 2026 after exploiting 45 unique zero-day vulnerabilities, BleepingComputer reported. The day’s headline act was the Samsung Galaxy S26, which was hacked three separate times — by KAIST Hacking Lab’s Kyeongmin Kim, by PetoWorks, and by a team of Dimitrios Valsamaras, Ken Gannon, and CENSUS Labs’ Tenia Valsamara.
Jack Dates of RET2 Systems demonstrated a Sonos Era 300 exploit chain in under a minute, while Out of Bounds’ HaeJung Yang took $40,000 for hacking Dynamo in the AI Infrastructure category. The Home Assistant Green smart home hub also fell, to PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec’s Yassine Bengana and Maxence Schmitt. Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.
Before the session, Kyeongmin Kim withdrew his USB-based attack attempt on the Google Pixel 10. CyberInsider reported the October 7 session brought the competition tally to $621,000 awarded for 77 unique zero-day vulnerabilities, including Interrupt Labs’ $5,000 Lexmark CX532adwe printer hack, which displayed DOOM on the device’s screen, and _McCaulay’s $10,000 Canon imageFORCE 1643F compromise via hard-coded credentials, missing authentication and command injection.
Organised by Trend Micro’s Zero Day Initiative in Cork, Ireland from 6 to 9 October 2026, the contest runs targets on the latest firmware and requires demonstrated arbitrary code execution; vendors get 90 days to patch before public disclosure. Apple’s iPhone 17, which carried a $300,000 maximum award for a remote hack, attracted no registered attempts.
More on this topic: all Technology stories


