Threat Intelligence

Pixel 10 Falls Three Times at Pwn2Own Ireland, Even When Fully Patched

The Hacker News · 9 Oct 2026
Key Takeaway Keep staff Pixel phones on automatic updates and install Google's security patches as soon as they are released, since fixes for these flaws may follow.

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork where every target must be fully patched. Ikotas Labs earned $300,000, the contest's top prize, and became the overall winner. Together, the three Pixel 10 wins paid $562,500. A fourth remote attempt, on the first day, ran out of time.

All three entries were registered as remote exploits, meaning the phone was attacked through web content in its default browser or over NFC, Wi-Fi, Bluetooth or baseband radio links. Which route each team used, and what each exploit did, has not been published. Trend Micro's Zero Day Initiative (ZDI), which runs the contest, had not released technical details as of October 9. At least two of the three used a bug that was already known, which ZDI calls a collision. Xint's win was set at half the listed prize, $150,000, while Ikotas Labs received the full amount, and the results do not explain why.

The wins were demonstrations on contest phones. Winning teams hand their exploits to ZDI, which passes the bugs to vendors. Vendors then have 90 days to patch before full details are published, according to a June TrendAI article. Google's October Pixel bulletin came out on October 6 and does not mention the contest. ZDI's results list no fix and no step for Pixel owners to take.

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.