Samsung Galaxy S26 Hacked Three Times at Pwn2Own Ireland, Zero-Day Flaws Revealed
Security researchers have been busy at Pwn2Own Ireland 2026, a competition that tests the vulnerability of popular devices and software to zero-day attacks. On the second day of the event, three separate teams successfully hacked the Samsung Galaxy S26 flagship smartphone, exposing critical weaknesses in its security. These exploits demonstrate the importance of keeping device firmware up-to-date and highlight the ongoing cat-and-mouse game between hackers and device manufacturers.
The Pwn2Own competition is organized by Trend Micro’s Zero Day Initiative (ZDI), which aims to identify zero-day flaws in fully patched devices before attackers exploit them in the wild. Contestants must compromise their target device, demonstrating arbitrary code execution, and all devices participating run the latest firmware versions. After the exploits are disclosed at Pwn2Own, vendors have 90 days to patch their software before ZDI publicly reveals the vulnerabilities.
The Samsung Galaxy S26 hacks were performed by KAIST Hacking Lab’s Kyeongmin Kim, PetoWorks, and Dimitrios Valsamaras and Ken Gannon. These teams successfully exploited unique zero-day vulnerabilities, earning significant cash awards for their efforts. In total, $232,500 was awarded to security researchers who demonstrated 45 unique zero-day exploits throughout the competition.
It’s worth noting that some of the bugs exploited during Pwn2Own Ireland were already known to Samsung. However, this highlights the importance of ongoing research and testing to identify vulnerabilities before they can be exploited by malicious actors. The competition also showcases the efforts of vendors like Samsung in working with security researchers to improve device security.
The Pwn2Own contest targets products across seven categories, including mobile phones, smart home devices, printers, AI infrastructure, and wellness healthcare devices. While Apple’s iPhone 17 was a potential target for remote hacking, no contestant attempted to exploit it during the competition. The event continues on its third day, with security researchers attempting to hack multiple smart home, AI infrastructure, and printer devices.
As the cybersecurity landscape evolves, device manufacturers must prioritize ongoing research and development to stay ahead of emerging threats. Users can take steps to protect themselves by ensuring their devices are running the latest firmware versions and keeping software up-to-date. This includes being cautious when installing new apps or accepting software updates, as these can often introduce new vulnerabilities.
In conclusion, the successful hacks at Pwn2Own Ireland 2026 serve as a reminder of the importance of device security and the ongoing efforts of security researchers to identify and disclose zero-day flaws. By staying informed about emerging threats and taking steps to protect themselves, users can better safeguard their devices against potential attacks.
Source: Bleeping Computer — 2026-10-08