Pixel 10 Falls Three Times at Pwn2Own Ireland, Even When Fully Patched
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork where every target must be fully patched. Ikotas Labs earned $300,000, the contest's top prize, and became the overall winner. Together, the three Pixel 10 wins paid $562,500. A fourth remote attempt, on the first day, ran out of time.
All three entries were registered as remote exploits, meaning the phone was attacked through web content in its default browser or over NFC, Wi-Fi, Bluetooth or baseband radio links. Which route each team used, and what each exploit did, has not been published. Trend Micro's Zero Day Initiative (ZDI), which runs the contest, had not released technical details as of October 9. At least two of the three used a bug that was already known, which ZDI calls a collision. Xint's win was set at half the listed prize, $150,000, while Ikotas Labs received the full amount, and the results do not explain why.
The wins were demonstrations on contest phones. Winning teams hand their exploits to ZDI, which passes the bugs to vendors. Vendors then have 90 days to patch before full details are published, according to a June TrendAI article. Google's October Pixel bulletin came out on October 6 and does not mention the contest. ZDI's results list no fix and no step for Pixel owners to take.