Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Sakana AI’s LLM Peer Review System Catches 73% of Core-Claim Errors

    October 11, 2026

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    October 11, 2026

    Building The Berkshire Hathaway Of Bitcoin

    October 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Sakana AI’s LLM Peer Review System Catches 73% of Core-Claim Errors
    • Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
    • Building The Berkshire Hathaway Of Bitcoin
    • Bowel cancer “melted away” after immunotherapy, then stayed away
    • Twelve killed and hundreds injured in Houthi attack at Riyadh airport | Saudi Arabia
    • Disney Plus Discount Codes: 52% Off October 2026
    • Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
    • Payment fraud detection fell with newer AI in Coinbase test
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, October 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 09, 2026Vulnerability / Mobile Security

    Three research teams broke into Google’s Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest’s top prize, and made the team the overall winner.

    Trend Micro’s Zero Day Initiative (ZDI), which runs Pwn2Own, posted the results but had not published how the three exploits work as of October 9. The wins were demonstrations on contest phones, and at least two of the three used a bug that was already known before the attempt.

    The contest rules require each entry to use bugs that are not already known to the vendor or to the organizer. An entry that uses an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize.

    The three Pixel 10 wins, in the order they happened:

    Team ZDI’s Description Award Points
    Xint (Tim Becker and Yves Bieri) Used “a single bug collision” $150,000 15
    Ikotas Labs “chained multiple issues together” (entry labeled a collision) $300,000 30
    Dimitrios Valsamaras, Ken Gannon and Tenia Valsamara A chain of two bugs: one collision and one zero-day $112,500 22.5

    Together, the three wins paid $562,500. All three teams were competing for the same listed prize of $300,000 and 30 points.

    Xint went first. Its win was first announced with the full prize still to be confirmed, then set at $150,000 and 15 points, half the listed amounts.

    Cybersecurity

    Ikotas Labs went second and received the full $300,000 and 30 points. Its entry is also labeled a collision in the results, with no explanation of the label or of why the full prize was paid.

    All three Pixel 10 entries were registered as remote exploits. Under the rules, that means breaking into the phone through web content opened in its default browser or over one of four radio links: NFC, Wi-Fi, Bluetooth or baseband.

    A winning entry must run code of the attacker’s choice on the phone or pull sensitive information from it. Which route each team used, and what each exploit did on the phone, has not been published.

    Three of the four remote attempts on the Pixel 10 succeeded. The other, on the contest’s first day, ran out of time.

    What Happens Next

    Under the rules, winning teams hand their exploits and write-ups to ZDI, and the bugs are passed to the affected vendors. Vendors then have 90 days to release patches before ZDI publishes the full technical details, according to a June article from TrendAI, Trend Micro’s enterprise security business.

    Google’s October Pixel bulletin was published on October 6, two days before the Pixel 10 exploits were shown, and does not mention the contest. ZDI’s results list no fix and no step for Pixel owners to take.

    Galaxy S26 and Other Results

    Samsung’s Galaxy S26 was exploited in all seven attempts made on it during the contest. Six of the seven winning entries included at least one collision. ZDI said one bug in the Galaxy S26 chain Ikotas Labs used on the first day “was already known to the vendor (yet unpatched)” at the time.

    Ikotas Labs also exploited OpenAI’s Codex coding agent and, on the second day, Oracle’s Autonomous AI Database. Its four wins add up to $361,000 and 42.5 points in ZDI’s posted results. ZDI named it Master of Pwn, the title for the contestant with the most points.

    Cybersecurity

    Researchers also exploited Lexmark, Canon and Brother printers, three smart home devices (Sonos Era 300, Philips Hue Bridge Pro and Home Assistant Green) and the Garmin Index BPM, a wellness device.

    Every product on the schedule was exploited at least once, and 51 of the 63 scheduled attempts succeeded. The schedule listed no attempt on Apple’s iPhone 17 or on WhatsApp, each with a top prize of $300,000.

    ZDI’s posted awards for the three days add up to more than $1.2 million, above the $1,024,750 it awarded at last year’s Ireland contest.

    Separately, Google in September patched a Pixel modem flaw, CVE-2026-58704, that it said : “may be under limited, targeted exploitation.” Pixel phones at patch level 2026-09-05 or later have that fix.

    Demonstrate Fully Google hacks Patched Pixel Pwn2Own remote Teams
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

    Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    US Disrupts Chinese State-Sponsored Hacking Tools

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

    ARTEX AI, Claude agents used in cyberattacks on South Korean banks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Sakana AI’s LLM Peer Review System Catches 73% of Core-Claim Errors

    October 11, 2026

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    October 11, 2026

    Building The Berkshire Hathaway Of Bitcoin

    October 11, 2026

    Bowel cancer “melted away” after immunotherapy, then stayed away

    October 11, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Sakana AI’s LLM Peer Review System Catches 73% of Core-Claim Errors

    October 11, 2026

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    October 11, 2026

    Building The Berkshire Hathaway Of Bitcoin

    October 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.