BleepingComputer reported that researchers won $232,500 on the second day of Pwn2Own Ireland 2026. They used 45 unique zero-days, meaning flaws the vendors did not know about. Three teams broke into the Samsung Galaxy S26: KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon. Others hacked a Sonos Era 300 speaker, the Home Assistant Green smart home hub, and the Oracle Autonomous AI Database. HaeJung Yang won $40,000 for hacking Dynamo in the AI infrastructure category.
Trend Micro's Zero Day Initiative runs the contest. BleepingComputer said vendors get 90 days to fix each flaw before the details become public. The article says some bugs used against the S26 on day one were already known to Samsung. It does not say whether that is true for the day-two attacks. It also does not name the flaws or say which ones Samsung has fixed. Kyeongmin Kim withdrew a planned attack on the Google Pixel 10. No one signed up to attack Apple's iPhone 17.
Pwn2Own tests fully updated devices, so these flaws affect products that were current at the time. Teams that buy or manage phones, smart home hubs and AI database tools should watch for vendor fixes in the next 90 days.