Pwn2Own Ireland Researchers Exploit 32 Zero-Days on First Day

Summary
Researchers exploited 32 zero-days across devices and services on the first day of Pwn2Own Ireland 2026, earning $388,500. Vendors have 90 days to release security updates before ZDI publicly discloses exploited flaws.
Key points
- Researchers hacked the Samsung Galaxy S26 twice during the competition.
- VinSOC researchers won $40,000 for a seven-zero-day chain against a Philips Hue Bridge Pro and another $40,000 for a five-zero-day chain targeting Oracle Autonomous AI Database.
- Competitors also demonstrated LiteLLM zero-days, compromised two multifunction printers and a Sonos speaker, and took down the OpenAI Codex coding agent with an argument-injection bug.
- Some bugs used in the challenges were already known to vendors.
- ZDI gives vendors 90 days to release security updates before publicly disclosing flaws exploited at Pwn2Own.
Article Details
- Event Type
- First-day zero-day demonstrations at the Pwn2Own Ireland 2026 hacking competition
- Impact
- Researchers exploited 32 zero-days and earned $388,500. The Samsung Galaxy S26 was hacked twice; other successful demonstrations affected a smart lighting hub, an AI database, printers, an AI coding agent, and a smart speaker. Some bugs used in the challenges were already known to the affected vendors.
People
Huỳnh Đức TinVinSOC researcher who helped demonstrate exploit chains against Philips Hue Bridge Pro and Oracle Autonomous AI Database.Mate ZomborWhite Noise Club researcher whose Google Pixel 10 exploit did not work within the allotted time.Mikhail EvdokimovWhite Noise Club researcher whose Google Pixel 10 exploit did not work within the allotted time.Nguyen Thanh DatViettel Cyber Security researcher involved in a successful Samsung Galaxy S26 demonstration.Polina SmirnovaWhite Noise Club researcher whose Google Pixel 10 exploit did not work within the allotted time.Vũ Chí ThànhVinSOC researcher who helped demonstrate exploit chains against Philips Hue Bridge Pro and Oracle Autonomous AI Database.
Vendors
CanonSecurity researchers also demoed LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injectionGoogletarget products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a newLexmarkSecurity researchers also demoed LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injectionOpenAIzero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug, and exploited fourOracleBridge Pro smart lighting hub, plus an additional $40,000 for a five zero-day exploit chain targeting the Oracle Autonomous AI Database.PhilipsĐức Tin of VinSOC, who topped the leaderboard, won $40,000 after chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub, plus an additional $40,000 for a five zero-day exploit chain targetingSamsungOn the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.SonosAI coding agent with a single argument-injection bug, and exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker again.
Products
Canon imageFORCE 1643FSecurity researchers also demoed LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injectionCodexhacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug, and exploited four vulnerabilitiesGoogle Pixel 10products in seven categories, including mobile phones (Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new categoryLexmark CX532adweSecurity researchers also demoed LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injectionLiteLLMSecurity researchers also demoed LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injectionOracle Autonomous AI Databaselighting hub, plus an additional $40,000 for a five zero-day exploit chain targeting the Oracle Autonomous AI Database.Philips Hue Bridge Proof VinSOC, who topped the leaderboard, won $40,000 after chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub, plus an additional $40,000 for a five zero-day exploit chain targeting theSamsung Galaxy S26On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days.Sonos Era 300coding agent with a single argument-injection bug, and exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker again.