On the second day of Pwn2Own Ireland 2026, security researchers demonstrated exploits targeting fully patched devices, with the Samsung Galaxy S26 flagship being the highlight after being compromised three times. The successful hacks were performed by Kyeongmin Kim of KAIST Hacking Lab, PetoWorks, and the team of Dimitrios Valsamaras and Ken Gannon from Mobile Hacking Lab.
Other notable demonstrations included Jack Dates of RET2 Systems, who executed an exploit chain against a Sonos Era 300 in under a minute. In the AI Infrastructure category, HaeJung Yang of the Out of Bounds team was awarded $40,000 for hacking Dynamo. Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit.
Several teams also targeted the Home Assistant Green smart home hub, with PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt all achieving successful compromises. Before day two began, Kyeongmin Kim withdrew his attempt at a USB-based attack targeting the Google Pixel 10.
Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws in fully patched devices before attackers exploit them in the wild. According to Pwn2Own rules, all devices run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution. After zero-days are exploited and disclosed at the event, vendors have 90 days to patch their software before ZDI publicly discloses the vulnerabilities.
The competition targets products in seven categories, including mobile phones (Samsung Galaxy S26 and Google Pixel 10).