Skip to content
Brief Security & Trust ·

Samsung Galaxy S26 hacked three more times on day two of Pwn2Own Ireland

Researchers earned $232,500 on day two by using 45 previously unknown flaws, BleepingComputer reported.

In brief
  • On day two of Pwn2Own Ireland 2026, researchers won $232,500 using 45 unique zero-day flaws, BleepingComputer reported.
  • The Samsung Galaxy S26 was hacked three more times, and vendors now have 90 days to fix the flaws.

BleepingComputer reported that researchers won $232,500 on the second day of Pwn2Own Ireland 2026. They used 45 unique zero-days, meaning flaws the vendors did not know about. Three teams broke into the Samsung Galaxy S26: KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon. Others hacked a Sonos Era 300 speaker, the Home Assistant Green smart home hub, and the Oracle Autonomous AI Database. HaeJung Yang won $40,000 for hacking Dynamo in the AI infrastructure category.

Trend Micro's Zero Day Initiative runs the contest. BleepingComputer said vendors get 90 days to fix each flaw before the details become public. The article says some bugs used against the S26 on day one were already known to Samsung. It does not say whether that is true for the day-two attacks. It also does not name the flaws or say which ones Samsung has fixed. Kyeongmin Kim withdrew a planned attack on the Google Pixel 10. No one signed up to attack Apple's iPhone 17.

Pwn2Own tests fully updated devices, so these flaws affect products that were current at the time. Teams that buy or manage phones, smart home hubs and AI database tools should watch for vendor fixes in the next 90 days.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: BleepingComputer.