Samsung Galaxy S26 Hacked Three Times on Second Day of Pwn2Own Ireland 2026

Researchers collect $232,500 in bounties after exploiting 45 zero-day vulnerabilities during competition

By LineZotpaper
Published
Read Time2 min
Security researchers hacked the Samsung Galaxy S26 three times on the second day of Pwn2Own Ireland 2026, collecting $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities across various devices and categories.

On the second day of Pwn2Own Ireland 2026, security researchers demonstrated exploits targeting fully patched devices, with the Samsung Galaxy S26 flagship being the highlight after being compromised three times. The successful hacks were performed by Kyeongmin Kim of KAIST Hacking Lab, PetoWorks, and the team of Dimitrios Valsamaras and Ken Gannon from Mobile Hacking Lab.

Other notable demonstrations included Jack Dates of RET2 Systems, who executed an exploit chain against a Sonos Era 300 in under a minute. In the AI Infrastructure category, HaeJung Yang of the Out of Bounds team was awarded $40,000 for hacking Dynamo. Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.

Several teams also targeted the Home Assistant Green smart home hub, with PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt all achieving successful compromises. Before day two began, Kyeongmin Kim withdrew his attempt at a USB-based attack targeting the Google Pixel 10.

Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws in fully patched devices before attackers exploit them in the wild. According to Pwn2Own rules, all devices run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution. After zero-days are exploited and disclosed at the event, vendors have 90 days to patch their software before ZDI publicly discloses the vulnerabilities.

The competition targets products in seven categories, including mobile phones (Samsung Galaxy S26 and Google Pixel 10).

§

Analysis

Why This Matters

  • The event reveals that even fully patched, flagship consumer devices like the Samsung Galaxy S26 contain exploitable vulnerabilities, highlighting the gap between vendor patching and real-world security.
  • The cash awards incentivize ethical hackers to find flaws before malicious actors can exploit them, but the 90-day disclosure window creates pressure on vendors to respond quickly.
  • The inclusion of AI infrastructure and smart home devices shows the expanding attack surface in connected ecosystems.

Background

Pwn2Own is a long-running hacking competition organized by Trend Micro's Zero Day Initiative. It brings together security researchers to demonstrate zero-day exploits against widely used, fully patched hardware and software. The Ireland edition is a regular event in the competition calendar. Vendors whose products are hacked receive the exploit details and a 90-day period to develop and ship patches before the vulnerabilities are publicly disclosed.

Key Perspectives

Security Researchers: The competition provides a legitimate, well-compensated platform to demonstrate skills, earn bounties, and improve overall device security through responsible disclosure. Device Vendors (Samsung, Google, Sonos, etc.): Participation allows them to learn about critical vulnerabilities in their products under controlled conditions, though the public nature of the event can create reputational pressure. Critics/Skeptics: Some argue that the competition-style environment may not reflect real-world attack scenarios, and that the 90-day patch window may be insufficient for complex vulnerabilities.

What to Watch

  • How quickly Samsung, Google, and other affected vendors ship patches for the disclosed zero-days.
  • Whether the number and severity of exploited vulnerabilities increases in future Pwn2Own events.
  • Potential expansion of competition categories to cover more emerging technologies like AI infrastructure.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.