MikhbarMIKHBAR
Cybersecurity

Hackers Exploit 32 Zero-Days on Day One of Pwn2Own Ireland

Security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days on the first day of the Pwn2Own Ireland 2026 competition.

Hackers Exploit 32 Zero-Days on Day One of Pwn2Own Ireland

Competition Overview and Categories

The Pwn2Own Ireland 2026 hacking contest brings together security researchers to target products in seven categories, as detailed by BleepingComputer. Competitors focus on mobile phones including the Apple iPhone 17, Samsung Galaxy S26, and Google Pixel 10, alongside printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a brand-new wellness healthcare devices category.

Day One Highlights and Mobile Targets

The primary highlight of the first day involved multiple teams targeting Samsung's flagship device. Participants successfully hacked the Samsung Galaxy S26 twice, earning a combined total of $388,500 after exploiting 32 zero-days. Notable teams executing these mobile exploits included Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security. However, organizers noted that some of the bugs exploited in each challenge were already known to the vendor.

Smart Home and Database Exploits

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC dominated the opening day leaderboard. They secured $40,000 after chaining seven zero-days to compromise a Philips Hue Bridge Pro smart lighting hub. Additionally, the same researchers earned another $40,000 by successfully demonstrating a five zero-day exploit chain targeting the Oracle Autonomous AI Database.

Pwn2Own Ireland 2026 Day 1 leaderboard
Pwn2Own Ireland 2026 leaderboard (ZDI) · Source: BleepingComputer

AI Infrastructure and Printer Compromises

Beyond mobile and smart home hardware, security researchers targeted a wide variety of connected infrastructure and software solutions. Participants demonstrated zero-days affecting LiteLLM, compromised the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, and took down the OpenAI Codex cloud-based AI coding agent using a single argument-injection bug. Furthermore, researchers exploited four vulnerabilities to successfully compromise a Sonos Era 300 smart speaker.

Unsuccessful Attempts and Ongoing Schedule

Not all attempts on the opening day succeeded within the permitted time frames. Mikhail Evdokimov, Polina Smirnova, and Mate Zombor of White Noise Club targeted the Google Pixel 10, but ultimately could not get their exploit to function inside the allotted time. The competition continues with upcoming days featuring additional attacks against AI infrastructure, printers, smart home devices, wellness products, and mobile flagships like the Google Pixel 10 and Samsung Galaxy S26.

Security Impact and Disclosure Timeline

The Zero Day Initiative organizes the annual Pwn2Own competition specifically to uncover zero-day vulnerabilities in targeted devices before malicious threat actors can discover and exploit them in the wild. Once security researchers successfully demonstrate these flaws at the event, device vendors are given a strict 90-day window to release security patches and updates before Trend Micro's ZDI publicly discloses the technical details.

Sources

Continue chronologically

You are readingHackers Exploit 32 Zero-Days on Day One of Pwn2Own Ireland
Firefox Offers Free Cybersecurity Tools for 2026 Awareness Month
Older storyFirefox Offers Free Cybersecurity Tools for 2026 Awareness MonthOctober 6, 2026 · 4 min

Related entity coverage