Remote Exploits Crack Fully Patched Pixel 10 at Pwn2Own

At the recent Pwn2Own Ireland event in Cork, held on October 8, multiple research teams successfully breached Google’s Pixel 10 smartphone — even though the devices were fully up to date. The rules at Pwn2Own require that every target be patched, yet three separate entries managed to perform remote hacks, earning big rewards while exposing worrisome gaps in device security.

Who got in, how, and what they earned

All three winning entries targeted the Pixel 10 using remote exploit techniques. Under the contest’s definitions, “remote” means the attack could happen via the default browser when viewing web content, or through one of the device’s wireless radios — NFC, Wi-Fi, Bluetooth, or its baseband network interface. Each exploit either ran attacker-supplied code on the phone, or exfiltrated sensitive data.

The entrants were:

  • Xint (Tim Becker and Yves Bieri) — used a “single bug collision” (i.e. an issue already known) to win $150,000 and 15 points.
  • Ikotas Labs — chained multiple issues together (also marked a collision) to score the full prize of $300,000 and 30 points, making them the event’s overall winner.
  • Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara — used a combination of a known collision and one previously unknown zero-day bug to pocket $112,500 and 22.5 points.

Together, these three exploits on the Pixel 10 brought payouts totaling $562,500. Despite all victims being fully patched, at least two of the attacks leveraged flaws that were already on record before the competition — though contest rules allow “collisions” but pay less for them.

Broader fallout & contest results

While Pixel 10 hogged headlines, it wasn’t alone. The Galaxy S26 faced seven exploit attempts, with six successful entries — most involving collisions. One case, by Ikotas Labs, used a bug already disclosed to Samsung yet left unpatched at the time.

Beyond phones, researchers targeted a range of other devices: Codex, Oracle’s Autonomous AI Database, several printer brands, smart home hardware (like Philips Hue Bridge Pro, Sonos Era 300, Home Assistant Green), and even a wellness tracker (Garmin Index BPM). Out of 63 scheduled exploit attempts across devices, 51 succeeded.

The total prize pool awarded over the event topped $1.2 million — exceeding last year’s tally in Ireland — with Ikotas Labs earning the title “Master of Pwn” by accumulating the most points throughout. Google had just released its October security bulletin on Pixel devices two days before the contest, yet it didn’t reference the vulnerabilities showcased at the event; likewise, there are no user-actionable mitigations listed for Pixel owners in the public results.

Under rules set by the contest overseers, ZDI (Trend Micro’s Zero Day Initiative), the disclosed bugs are handed to vendors who then have 90 days to issue patches before the full technical details are published.

Why this matters

This event again underscores a frustrating reality: even fully patched phones can remain vulnerable. It isn’t enough to simply keep devices up to date — what counts equally is how quickly known vulnerabilities are patched once vendors are aware. The collision bugs that were already disclosed but unaddressed at the time of attack made a big difference in rewards and the pattern of successful exploits.

For manufacturers, this raises pressing questions about patch speed, transparency, and threat modeling — particularly for remote attack surfaces like web browsers and radios. Consumers should keep devices updated; meanwhile, vendors must treat known issues with the urgency they deserve. Observers will be watching Google’s upcoming updates closely to see if it resolves these newly exposed weak spots.