At the recent Pwn2Own competition held in Cork, Ireland, three research teams successfully infiltrated fully patched Google Pixel 10 devices. The event, which took place on October 8, 2026, showcases hacking skills and awards researchers for their ability to identify vulnerabilities. Ikotas Labs stood out by winning the top prize of $300,000 and was named the overall winner of the contest.
Details of the Exploits
The Zero Day Initiative (ZDI), affiliated with Trend Micro, manages the Pwn2Own event. On October 9, they released the results, but specific details about the exploit mechanisms remain undisclosed. Notably, one of the winning exploits by the teams involved a previously known vulnerability, a situation referred to as a ‘collision’ by ZDI.
The rules of the contest stipulate that exploits should be based on bugs unknown to the vendor or the organizer. However, entries involving known bugs, albeit at a reduced prize, are still permissible. Participants demonstrated their skills by exploiting Pixel 10 devices through various remote methods, such as web content via the default browser or through wireless technologies including NFC, Wi-Fi, Bluetooth, or baseband.
Prize Distribution and Exploit Strategies
Xint, comprising Tim Becker and Yves Bieri, were the first to achieve a successful hack, earning $150,000 and 15 points. Their approach included a bug collision. Ikotas Labs followed, securing the full $300,000 and 30 points despite their entry being labeled a collision, with no further explanation provided.
The third team, consisting of Dimitrios Valsamaras, Ken Gannon, and Tenia Valsamara, utilized a combination of a collision and a zero-day vulnerability, earning them $112,500 and 22.5 points. Combined, these exploits awarded the participants a total of $562,500.
Future Implications and Vendor Response
The winning teams are required to hand over their exploit details to ZDI, who then communicates this information to the affected vendors. According to Trend Micro’s guidelines, vendors have a 90-day window to address these vulnerabilities before ZDI makes the technical details public.
Google’s security bulletin for October was released just days before the contest and did not mention these specific exploits. There is currently no guidance for Pixel users regarding these vulnerabilities. Other devices, such as Samsung’s Galaxy S26 and various smart home devices, were also targets at the event, with several successful hacks reported.
Overall, Pwn2Own 2026 awarded over $1.2 million, surpassing the previous year’s total. The event highlights the ongoing need for robust cybersecurity measures and the value of identifying vulnerabilities in modern technology.
