Full Report
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
Analysis Summary
# Vulnerability: Multiple Remote Exploits of Google Pixel 10 (Pwn2Own Ireland 2026)
## CVE Details
- **CVE ID**: Pending (Bugs were disclosed privately to the vendor; CVEs are typically assigned upon patch release).
- **CVSS Score**: Not yet assigned (Estimated **Critical** based on remote execution capabilities).
- **CWE**: Not yet specified (Involves "bug collisions" and "chains of multiple issues").
## Affected Systems
- **Products**: Google Pixel 10.
- **Versions**: Fully patched as of October 8, 2026 (including the October 6, 2026 security bulletin).
- **Configurations**: Default configurations using the device's standard connectivity or browser.
## Vulnerability Description
During the Pwn2Own Ireland 2026 contest, three separate research teams successfully demonstrated remote exploits on the Google Pixel 10. While specific technical details are currently under a 90-day non-disclosure agreement (NDA), the exploits are categorized as follows:
- **Xint Team**: Utilized a "single bug collision."
- **Ikotas Labs**: Successfully "chained multiple issues together."
- **Valsamaras/Gannon/Valsamara Team**: Utilized a two-bug chain consisting of one previously known bug (collision) and one zero-day vulnerability.
The flaws allow an attacker to bypass security boundaries to run arbitrary code or extract sensitive information.
## Exploitation
- **Status**: Exploited in a controlled environment (Pwn2Own); exploits have been handed to Google.
- **Complexity**: High (Requires chaining multiple vulnerabilities or identifying specific "collisions").
- **Attack Vector**: Remote. Targets include web content via the default browser or radio links (NFC, Wi-Fi, Bluetooth, or Baseband).
## Impact
- **Confidentiality**: **High** (Attackers can pull sensitive information from the device).
- **Integrity**: **High** (Attackers can run code of their choice).
- **Availability**: **High** (System compromise allows for full device control).
## Remediation
### Patches
- **Status**: **No patch currently available.**
- Google has been notified and has a 90-day window (ending approximately January 2027) to issue a security update before full technical details are made public by the Zero Day Initiative (ZDI).
### Workarounds
- No specific workarounds have been provided by the vendor. Standard mobile security hardening is advised:
- Avoid clicking suspicious links in browsers.
- Disable unused radio services (NFC/Bluetooth) when in untrusted public areas.
## Detection
- **Indicators of Compromise**: No specific IOCs are currently available due to the private nature of the exploit disclosure.
- **Detection methods**: Monitor for unusual network traffic originating from system-level processes or unexpected device reboots.
## References
- **Vendor Advisory**: hxxps://source[.]android[.]com/docs/security/bulletin/pixel/2026/2026-10-01
- **ZDI Results**: hxxps://www[.]zerodayinitiative[.]com/blog/2026/10/8/pwn2own-ireland-2026-day-three-results-amp-master-of-pwn
- **Event Rules**: hxxps://www[.]zerodayinitiative[.]com/Pwn2OwnIreland2026Rules[.]html