The Samsung Galaxy S26 suffered three more successful zero-day exploits on the second day of Pwn2Own Ireland 2026, leaving Samsung with a growing pile of software flaws to patch.
The hacking tournament, organised by Trend Micro's Zero Day Initiative (ZDI), tests fully updated consumer tech against elite security researchers. Under contest guidelines, every target device must run the latest production firmware. To claim a cash bounty, competitors must compromise the hardware live and achieve arbitrary code execution.
Three separate outfits pierced Samsung's flagship on day two. Kyeongmin Kim from KAIST Hacking Lab broke through first, followed by researcher group PetoWorks, and a team effort by Dimitrios Valsamaras and Ken Gannon of Mobile Hacking Lab.
The fresh round of exploits compounds a rough opening stretch for the handset. On day one, Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security each demonstrated working compromises against the Galaxy S26. ZDI noted that some flaws used during those earlier attempts were already known internally to Samsung, but day two brought brand-new exposure.
Across all target brackets on day two, researchers picked up $232,500 in prize money after proving 45 distinct zero-day vulnerabilities. Jack Dates from RET2 Systems cracked a Sonos Era 300 speaker in under sixty seconds. HaeJung Yang of team Out of Bounds collected $40,000 for compromising Dynamo in the AI infrastructure division. Smart home hardware took beatings as well, with the Home Assistant Green hub breached by multiple teams, while Ikotas Labs penetrated the Oracle Autonomous AI Database through a complex seven-bug chain.
Other flagship phones escaped the second day relatively unscathed. Kyeongmin Kim withdrew a planned attack against Google's Pixel 10 that was scheduled to rely on a USB connection before the session began. Apple's iPhone 17 was also on the competition roster, dangling a headline $300,000 bounty for a remote compromise, yet no contestant signed up to challenge it.
For Galaxy owners, these demonstrations are part of the standard vulnerability research pipeline rather than an emergency in the wild. Pwn2Own operates under strict coordinated disclosure rules. Samsung receives confidential technical documentation immediately after each successful stage run, starting a 90-day countdown. The company has three months to develop, test, and release security patches to retail handsets before ZDI publishes the exploit specifics.
Expect those fixes to roll out across standard monthly Android security maintenance releases over the coming weeks. Meanwhile, the pressure is not over: researchers line up for another round of attempts against both the Galaxy S26 and the Pixel 10 on day three.
MDFiled by The Mobile Desk
Phones from leak to launch to price cut: what was announced, what it costs where, and when it goes on sale. Indian launches and prices included, not appended.
More from this desk →
Be the first to comment
Join the argument. No password, just your email or a passkey.