32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Security researchers reportedly exploited 32 unique zero-day vulnerabilities and earned $388,500 on the opening day of Pwn2Own Ireland 2026. Samsung Galaxy S26, OpenAI Codex, smart home devices and AI services fell to working exploits, but the Google Pixel 10 attempt failed within the contest time limit.

The October 6 results show how security gaps span phones, connected devices, and the software used to build AI systems. ZDI announced 21 entries for day one, with several successful attacks combining new flaws with bugs vendors already knew about.

Samsung Galaxy S26 Exploit chains

Three teams successfully exploited the Samsung Galaxy S26, according to ZDI’s official results. Each used four bugs, but their payouts differed because parts of their exploit chains overlapped with previously reported flaws.

Nguyen Thanh Dat of Viettel Cyber Security earned $31,250 after using one new bug alongside three vendor-known flaws. Interrupt Labs received $15,750 for another chain containing one zero-day and three collisions. Ikotas Labs earned $11,000 after using three new bugs and one flaw Samsung already knew about but had not patched.

These results highlight an important distinction: a successful exploit does not mean every bug in its chain is new. ZDI marks overlapping discoveries as collisions, while still recognizing working attacks and awarding reduced prizes.

The Pixel 10 result was different. White Noise Club researchers Mikhail Evdokimov, Polina Smirnova and Mate Zombor could not complete their exploit within the allotted time. The published result does not establish that the phone has no vulnerabilities.

Ikotas Labs exploited OpenAI Codex using a single argument injection flaw, earning $40,000. ZDI identified the bug type but did not publish the full exploit steps, affected versions, or a CVE identifier in its day-one report.

Taisic Yun of Xint combined improper input validation with code injection to obtain a reverse shell on LiteLLM, earning another $40,000. A reverse shell gives the researcher a command connection back from the targeted system, demonstrating access beyond a simple application error.

Out of Bounds also exploited LiteLLM through four bugs, two previously known, receiving $15,000. Meanwhile, VinSOC chained five flaws against Oracle Autonomous AI Database for $40,000. Its separate attempt against Chroma did not succeed before time expired.

Smart Devices and Printer Flaws

VinSOC researchers Vũ Chí Thành and Huỳnh Đức Tin disclosed seven zero-days while exploiting Philips Hue Bridge Pro, earning $40,000. Other successful Hue attempts contained mostly known bugs, showing why the number of exploited flaws and the number of unique discoveries must remain separate.

McCaulay Hudson earned $50,000 by combining an out-of-bounds write with a format string flaw against Sonos Era 300. These bug classes involve unsafe memory access or unsafe handling of formatted text, although ZDI withheld detailed exploit mechanics.

Lexmark CX532adwe fell to separate attacks from Thanh Do of Team Confused and Sina Kheirkhah of Summoning Team. Interrupt Labs also earned $20,000 by combining an out-of-bounds read and write against Garmin Index BPM.

The demonstrations took place under contest rules; they are not evidence of attacks against real users.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post 32 Unique 0-Days Exploited in Samsung S26, Pixel 10, OpenAI Codex and Other Devices in Pwn2Own 2026 appeared first on Cyber Security News.