Three Teams Achieve Remote Pixel 10 Exploits at Pwn2Own Ireland
Researchers successfully demonstrated remote exploits against fully patched Google Pixel 10 devices at Pwn2Own Ireland, with one team securing the contest's top prize.

At the Pwn2Own Ireland hacking competition held in Cork, three distinct research teams managed to achieve remote exploits against Google's latest Pixel 10 smartphones, even though all devices were confirmed to be fully patched prior to the demonstrations. This significant achievement underscores the persistent threat of zero-day vulnerabilities, which continue to emerge and be exploited in cutting-edge mobile devices despite vendor efforts to maintain security.
One of the successful exploits, developed by Ikotas Labs, was particularly noteworthy, earning the team a substantial $300,000 prize and the overall victory in the contest. The findings from these exploits will be disclosed to Google, allowing the tech giant to develop and deploy necessary patches to protect its users. The contest's rules mandate that researchers present working exploits on up-to-date systems, ensuring that the vulnerabilities demonstrated are relevant to current security challenges.
Trend Micro's Zero Day Initiative (ZDI), the organizer of Pwn2Own, confirmed the successful breaches but had not yet released detailed technical information on how each exploit functioned as of October 9. While the contest requires the use of previously unknown bugs, it allows for "collisions" – exploits using bugs already known to the vendor or organizer – albeit with reduced prize money. The Pixel 10 exploits were categorized as remote, meaning they could be triggered through web content opened in the device's default browser or via wireless interfaces like NFC, Wi-Fi, or Bluetooth.
The three winning entries varied in their approach and rewards. Xint's team used "a single bug collision" and received $150,000. Ikotas Labs, the overall winner, "chained multiple issues together" and was also labeled a collision, yet received the full $300,000 prize. A third team, comprising Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara, combined a collision with a zero-day vulnerability, earning $112,500. In total, these three successful Pixel 10 exploits awarded $562,500.
Under Pwn2Own's standard procedure, winning researchers submit their exploit details to ZDI, which then forwards them to the affected vendor. Vendors are typically given a 90-day window to develop and release patches before ZDI publicly discloses the technical specifics of the vulnerabilities. Google's most recent Pixel security bulletin, released on October 6, predates the contest's demonstrations and does not mention any fixes related to these newly discovered exploits.
Beyond the Pixel 10, the competition also saw significant success in exploiting other devices. Samsung's Galaxy S26 was targeted in seven attempts, with six resulting in successful exploits, many involving known but unpatched vulnerabilities. Ikotas Labs also demonstrated exploits against OpenAI's Codex and Oracle's Autonomous AI Database, solidifying their position as the "Master of Pwn" for the event.
Across the board, Pwn2Own Ireland highlighted the ongoing arms race between vulnerability researchers and software vendors. The fact that multiple teams could find and exploit flaws in a fully patched, flagship device like the Google Pixel 10, even with some using previously known bugs, suggests that sophisticated attack vectors continue to be a reality for even the most secure consumer electronics.