Full Report
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]
Analysis Summary
# Vulnerability: Multiple Zero-Day Exploits Targeting Flagship Mobile and IoT Devices (Pwn2Own Ireland 2026 - Day 2)
## CVE Details
- **CVE ID:** Pending (Zero-day vulnerabilities; ZDI identifiers are assigned post-contest, and CVEs are typically issued after the 90-day disclosure window).
- **CVSS Score:** N/A (Individual scores not yet calculated, but historically range from **8.8 to 10.0** given the requirement for Arbitrary Code Execution).
- **CWE:** Included diverse weaknesses such as Improper Input Validation, Buffer Overflows, and Logic Flaws (based on the requirement for "arbitrary code execution").
## Affected Systems
- **Products:**
- Mobile: Samsung Galaxy S26, Google Pixel 10
- Smart Home: Home Assistant Green, Sonos Era 300, Philips Hue Bridge Pro
- AI/Database: Oracle Autonomous AI Database, Dynamo (AI Infrastructure)
- **Versions:** All devices were running the latest available firmware and software versions as of October 2026.
- **Configurations:** Default "out-of-the-box" configurations as per Pwn2Own competition rules.
## Vulnerability Description
During Day 2 of the Pwn2Own Ireland 2026 competition, 45 unique zero-day vulnerabilities were demonstrated. Notable exploits included:
- **Samsung Galaxy S26:** Compromised three times on Day 2 using various exploit chains to achieve unauthorized access.
- **Oracle Autonomous AI Database:** Exploited using a complex **seven-chain zero-day exploit** by Ikotas Labs.
- **Sonos Era 300:** A rapid exploit chain demonstrated code execution in under one minute.
- **Home Assistant Green:** Breached multiple times by various research teams using independent exploit paths.
## Exploitation
- **Status:** **PoC Available** (Demonstrated successfully in a controlled environment; exploits are shared with vendors but not yet public).
- **Complexity:** **High** (Required sophisticated chaining of multiple vulnerabilities—up to seven in some cases—to bypass modern OS protections).
- **Attack Vector:** **Network / Adjacent** (Most demonstrated exploits targeted wireless interfaces or networked services).
## Impact
- **Confidentiality:** **Total** (Attackers achieved arbitrary code execution, allowing full access to user data).
- **Integrity:** **Total** (Ability to modify system files and application data).
- **Availability:** **Total** (Potential for device bricking or complete service disruption).
## Remediation
### Patches
- **Currently Unavailable:** Vendors (Samsung, Google, Oracle, Sonos, etc.) were notified immediately following the successful exploits.
- **Timeline:** Vendors have a **90-day window** from the date of the contest to develop and release security patches before full technical details are publicly disclosed.
### Workarounds
- **Network Isolation:** Until patches are released, limit IoT devices (like smart hubs and speakers) to isolated VLANs.
- **Minimize Attack Surface:** Disable unnecessary features or services (e.g., UPNP, Guest Access) on affected hardware.
- **Physical Security:** Avoid using public or untrusted USB charging stations (noting the withdrawn USB-based attack on the Pixel 10).
## Detection
- **Indicators of Compromise:** Unusual outbound network traffic from IoT devices; unexpected reboots or system instability.
- **Detection methods and tools:** Network-level Intrusion Detection Systems (IDS) may identify the lateral movement or data exfiltration stages of these exploit chains.
## References
- **ZDI Blog:** hxxps[://]www[.]zerodayinitiative[.]com/blog/2026/10/5/pwn2own-ireland-2026-the-full-schedule
- **Vendor Advisories:** Pending (Monitor Samsung Mobile Security and Oracle Critical Patch Updates).
- **News Source:** hxxps[://]www[.]bleepingcomputer[.]com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/