VYPR
researchPublished Oct 7, 2026· 1 source

Pwn2Own Ireland 2026: 32 Zero-Days Exploited Across Samsung, OpenAI, and Smart Devices

Pwn2Own Ireland 2026 saw researchers exploit 32 unique zero-day vulnerabilities in devices from Samsung, OpenAI, and various smart home products, netting over $388,000 in prizes.

The opening day of Pwn2Own Ireland 2026 concluded with a significant demonstration of security weaknesses, as researchers successfully exploited 32 unique zero-day vulnerabilities across a range of consumer electronics and software services. The event, held on October 6, 2026, saw participants earn a total of $388,500 for their discoveries, highlighting persistent security gaps in widely used technologies.

Several high-profile targets were successfully compromised. The Samsung Galaxy S26 smartphone was a particular focus, with three separate research teams demonstrating exploit chains. While each team utilized multiple vulnerabilities, the prize amounts varied based on the novelty of the flaws. For instance, Nguyen Thanh Dat of Viettel Cyber Security earned $31,250 by combining one new bug with three previously known issues. Interrupt Labs secured $15,750 for a similar chain, and Ikotas Labs received $11,000 for an exploit involving three new bugs and one known but unpatched flaw.

Beyond mobile devices, the contest also showcased vulnerabilities in the burgeoning field of artificial intelligence services. Ikotas Labs successfully exploited OpenAI Codex with a single argument injection flaw, earning $40,000. Taisic Yun of Xint also demonstrated a significant win, securing $40,000 by chaining improper input validation with code injection to gain a reverse shell on LiteLLM, an open-source large language model application gateway. Out of Bounds also targeted LiteLLM, earning $15,000 for an exploit that leveraged two previously known vulnerabilities alongside new ones.

Smart home devices and printers were not spared. VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin disclosed seven zero-days while exploiting the Philips Hue Bridge Pro, earning $40,000. McCaulay Hudson demonstrated an impressive exploit against the Sonos Era 300, combining an out-of-bounds write with a format string flaw to win $50,000. Lexmark CX532adwe printers were also targeted by multiple research teams, including Thanh Do of Team Confused and Sina Kheirkhah of Summoning Team. Additionally, Interrupt Labs earned $20,000 for exploiting Garmin Index BPM devices.

While many devices fell victim to novel exploits, the contest also served to validate existing security research. The ZDI, which organizes Pwn2Own, noted that several successful exploits incorporated vulnerabilities that vendors were already aware of. These 'collisions' still resulted in payouts, albeit reduced, acknowledging the skill involved in chaining different types of flaws to achieve a full system compromise.

The Google Pixel 10 was one of the few devices that did not see a successful exploit within the contest's time limit. White Noise Club researchers were unable to complete their demonstration, though this does not preclude the existence of vulnerabilities in the device.

The Pwn2Own event serves as a critical platform for discovering and disclosing zero-day vulnerabilities before they can be exploited by malicious actors. The diverse range of targeted devices, from smartphones and AI services to smart home gadgets and printers, underscores the broad attack surface that organizations and consumers face in today's interconnected world.

While the demonstrations at Pwn2Own are conducted under controlled contest rules, they provide invaluable insights into the real-world threats that could emerge. The disclosed vulnerabilities will likely lead to patches and security updates from the affected vendors, helping to secure these products against future attacks.

Synthesized by Vypr AI