On the first day of Pwn2Own Ireland 2026, security researchers identified 32 unique zero-day vulnerabilities, earning a total of $388,500. The event saw successful exploitations of devices such as the Samsung Galaxy S26 and OpenAI Codex, although an attempt on the Google Pixel 10 was not completed within the time limit.
Overview of Day One Results
The initial day of Pwn2Own highlighted vulnerabilities across various devices and systems, including smartphones and AI technologies. The Zero Day Initiative (ZDI) recorded 21 entries, with some exploits utilizing both new and previously known bugs.
Samsung Galaxy S26 Exploit Chains
Three teams managed to exploit the Samsung Galaxy S26, each employing four different vulnerabilities. Nguyen Thanh Dat from Viettel Cyber Security earned $31,250 by combining a newly discovered bug with three known vulnerabilities. Interrupt Labs and Ikotas Labs also executed successful exploits, though their payouts varied due to overlapping bug usage.
ZDI emphasizes that not every vulnerability in a successful exploit chain is new. Overlapping discoveries are marked as collisions, impacting the prize amounts awarded.
Challenges and Successes in AI and Smart Devices
While the Google Pixel 10 remained impervious during the contest, Ikotas Labs exploited a flaw in OpenAI Codex, securing $40,000. Other notable exploits included Taisic Yun of Xint achieving a reverse shell on LiteLLM through code injection, also earning $40,000.
VinSOC researchers revealed seven zero-days in the Philips Hue Bridge Pro, earning $40,000, and McCaulay Hudson received $50,000 for exploiting a Sonos device. These efforts highlight ongoing security challenges in both AI and smart home technologies.
The event underscored the critical need for vigilance and innovation in cybersecurity, with experts continuing to uncover vulnerabilities across a range of technologies. As the contest progresses, further discoveries are anticipated, offering insights into emerging threats and the necessary defenses.
