Hackers got into Google’s newest flagship phone three times on Thursday. The break-ins happened at Pwn2Own Ireland, a contest in Cork run by Trend Micro’s Zero Day Initiative, or ZDI.
The contest pays researchers to show real attacks on up-to-date devices. The flaws are then passed to the makers so they can fix them. Pwn2Own ran from October 6 to October 9. The event recorded three successful remote hacks of Google’s Pixel 10. According to ZDI’s official results, the three entries earned $562,500 in total.
The three successful attacks on Pixel 10
The teams earned different rewards based on their results and the bugs involved. Xint went first. Tim Becker and Yves Bieri used what ZDI called a single bug collision. They earned $150,000 and 15 points. That is half the listed prize. ZDI first announced the win before setting the final amount.
Ikotas Labs went second. ZDI said the team chained multiple issues together. The results label the entry a collision, yet the team received the full $300,000 and 30 points. ZDI has not explained why.
Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara went third. They chained two bugs. One was a collision. The other was a zero-day, meaning a flaw the maker did not know about. They earned $112,500 and 22.5 points.
All three entries were listed as remote attacks. Under the rules, that means breaking in through a web page opened in the phone’s default browser or using NFC, Wi-Fi, Bluetooth or the phone’s cellular chip. A winning entry must run code the attacker chooses on the phone or retrieve sensitive data. Which route each team used is not public.
Three of four remote tries on the Pixel 10 worked. The failed one came on day one. A team called White Noise Club ran out of time before its exploit worked.
Contest rules require bugs that are unknown to the vendor and to ZDI. A bug that is already known is called a collision. Those entries are still acceptable, but at a lower price.
That was the pattern on Samsung’s Galaxy S26 earlier in the week. Interrupt Labs used four bugs, three of them collisions, and earned $15,750. Ikotas Labs used four bugs on the S26, one known to Samsung but still unpatched. It earned $11,000.
Against that backdrop, the full $300,000 paid to Ikotas Labs for the Pixel stands out. At least two of the three Pixel wins relied on a known bug.
Google to release disclosure and corresponding patches
Winning teams hand their exploits and write-ups to ZDI. ZDI passes the bugs to the vendors. According to Trend Micro’s explanation process, Vendors then get 90 days to release patches before ZDI publishes full technical details. That points to roughly early January.
Google’s October Pixel security bulletin came out on October 6, two days before the Pixel 10 attacks. It does not mention the contest. ZDI’s results list no fix and no steps for Pixel owners. The usual advice still applies: install updates when Google sends them.
Other technology providers have also urged users to update their software after fixing security flaws, including Plex, which urged users to update after patching previously undisclosed security flaws.
Separately, Google patched a Pixel modem flaw in September. Tracked as CVE-2026-58704, it “may be under limited, targeted exploitation,” according to Google. Phones with a patch level of 2026-09-05 or later have that fix.
Galaxy S26 and other devices fall
Samsung’s Galaxy S26 fell in all seven attempts made on it. Six of the seven winning entries included at least one collision. ZDI said one bug in the chain Ikotas Labs used on day one was known to Samsung but not yet fixed.
Ikotas Labs earned the title Master of Pwn, given to the contestant with the most points. Its four wins total $361,000 and 42.5 points. They included OpenAI’s Codex coding agent and, on day two, Oracle’s Autonomous AI Database.
Researchers also broke into Lexmark, Canon and Brother printers. They hacked three smart home devices: the Sonos Era 300, Philips Hue Bridge Pro, and Home Assistant Green. They also got into the Garmin Index BPM, a wellness device.
Every product on the schedule was exploited at least once. Of 63 scheduled attempts, 51 succeeded. The schedule listed no attempt on Apple’s iPhone 17 or on WhatsApp. Each carried a top prize of $300,000.
ZDI’s posted awards for the three days top $1.2 million. Last year’s Ireland contest paid $1,024,750. Phones drew extra attention this time. ZDI’s Dustin Childs wrote ahead of the event that “we’ve never had so many attempts on phones.”
The big unknown is how the Pixel attacks worked. ZDI has not said, and it will likely stay quiet until vendors have had their 90 days. Google’s October bulletin makes no mention of the contest. Watch for its November and December bulletins, which may show whether fixes are on the way.