Three Teams Exploit Fully Patched Google Pixel 10 Phones at Pwn2Own

· Original article ↗

Summary

Three teams remotely exploited Pixel 10 phones at Pwn2Own Ireland, earning a total of $562,500. ZDI has not published technical details or listed Pixel fixes, and at least two entries were marked as using previously known bugs.

Key points

  • Three of four remote attempts against the Pixel 10 succeeded; the remaining attempt ran out of time.
  • The winning entries were registered as remote exploits, which contest rules define as attacks through browser content or NFC, Wi-Fi, Bluetooth, or baseband.
  • Ikotas Labs received $300,000 and 30 points for its Pixel 10 entry; its result was also marked as a collision, meaning it used a bug already known to the vendor or organizer.
  • Xint received $150,000 and 15 points, half the listed prize and points.
  • ZDI had not published how the Pixel exploits worked as of October 9. It lists no Pixel fix or action for owners; vendors receive the exploit details and have 90 days to patch before ZDI publishes technical details.
  • Across the contest, 51 of 63 scheduled attempts succeeded, and every product on the schedule was exploited at least once.

Article Details

Event Type
Security contest demonstrations of remote exploits against fully patched Google Pixel 10 phones at Pwn2Own Ireland.
Impact
Three of four remote attempts against the Pixel 10 succeeded, with teams demonstrating the ability to run code or retrieve sensitive information under contest rules. The specific vulnerabilities and exploit effects have not been published, and the article reports no fix or action for Pixel owners. Google had passed the flaws to it under the contest disclosure process; the article does not report exploitation of these contest flaws outside the demonstrations.

CVE

Vendors

BrotherResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.CanonResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.GarminResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.GoogleThree research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploitsHome AssistantResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.LexmarkResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.OpenAIIkotas Labs also exploited OpenAI's Codex coding agent and, on the second day, Oracle's Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI's posted results. ZDI named it Master of Pwn, theOracleIkotas Labs also exploited OpenAI's Codex coding agent and, on the second day, Oracle's Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI's posted results. ZDI named it Master of Pwn, thePhilipsResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.SamsungSamsung's Galaxy S26 was exploited in all seven attempts made on it during the contest. Six of the seven winning entries included at least one collision. ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on theSonosResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.

Products

Autonomous AI DatabaseIkotas Labs also exploited OpenAI's Codex coding agent and, on the second day, Oracle's Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI's posted results. ZDI named it Master of Pwn, theCodexIkotas Labs also exploited OpenAI's Codex coding agent and, on the second day, Oracle's Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI's posted results. ZDI named it Master of Pwn, theGalaxy S26Samsung's Galaxy S26 was exploited in all seven attempts made on it during the contest. Six of the seven winning entries included at least one collision. ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on theGarmin Index BPMResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.Home Assistant GreenResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.Philips Hue Bridge ProResearchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.Pixel 10Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploitsSonos Era 300Researchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.

Related Articles