Threat reportVulnerabilityTL-2026-3103

Pwn2Own Ireland 2026: Google Pixel 10 Exploit Chains Earn $560,000

mediumMONITORING

Pwn2Own Ireland 2026 (TL-2026-3103), also tracked as Pwn2Own Ireland 2026 Pixel 10, is a medium-severity software vulnerability, first published 2026-10-09. It has no confirmed attribution, affects Google Pixel 10, maps to 5 MITRE ATT&CK techniques (T1404, T1587.004, T1588.005), and is covered by 9 detection rules and 9 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
9Indicators of compromise

Key facts for TL-2026-3103

Threat ID
TL-2026-3103
Also known as
Pwn2Own Ireland 2026 Pixel 10
Severity
MEDIUM
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer, enterprise-mobility
Target regions
Global
Detection rules
9
Indicators of compromise
9

How Pwn2Own Ireland 2026 works

Three teams demonstrated exploits against the Google Pixel 10 at Pwn2Own Ireland 2026 (Cork, organized by Trend Micro's Zero Day Initiative), earning $560,000 in total. Ikotas Labs received a full $300,000 payout for chaining multiple bugs for remote compromise; two other teams received reduced payouts for exploits that involved a previously known vulnerability. No CVEs, patches or technical details have been published.

Pwn2Own Ireland 2026, organized by Trend Micro's Zero Day Initiative (ZDI), began on October 6, 2026 in Cork, Ireland. According to SecurityWeek (2026-10-09), three teams successfully demonstrated exploits against the Google Pixel 10, collectively earning $560,000. Ikotas Labs received the full $300,000 payout for chaining multiple bugs to achieve a remote device compromise. Tim Becker and Yves Bieri earned $150,000 for an exploit that involved a previously known flaw (a reduced payout), and Dimitrios Valsamaras and Ken Gannon earned $112,500 for chaining a zero-day with a known vulnerability. The per-team amounts listed ($300,000 + $150,000 + $112,500 = $562,500) do not sum to the $560,000 total stated by the source; the stated total is retained here.

No CVE identifiers, CVSS scores, affected Android/Pixel build numbers, vulnerable components or exploit mechanics have been disclosed. Under Pwn2Own rules, vendors receive 90 days to release security updates before ZDI publicly discloses the flaws, so technical details are expected only after a patch or the disclosure deadline. Separate day-one coverage (BleepingComputer) reports that White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) also targeted the Pixel 10 but could not get their exploit to work within the allotted time. Secondary reporting indicates Ikotas Labs also compromised the Samsung Galaxy S26 with a four-vulnerability chain of which one bug was already known to Samsung, and speculates that a previously unknown flaw may also affect the Pixel 10; this is unconfirmed and no details are published.

This is competition-demonstrated research, not in-the-wild exploitation: no CISA KEV listing, public PoC, or threat-actor activity is reported. The entry is tracked in MONITORING status so that downstream phases can add CVEs, patch information and detection content when Google or ZDI publish details. The wider event reportedly totaled about $1.2 million across phones, printers, smart speakers, smart-home hubs, and AI infrastructure targets (Oracle Autonomous AI Database, OpenAI Codex, Nvidia Dynamo, LiteLLM, Philips Hue Bridge Pro, Samsung Galaxy S26, Sonos Era 300).

MITRE ATT&CK techniques used in TL-2026-3103

Privilege Escalation

T1404 Exploitation for Privilege Escalation

Resource Development

T1587.004 Develop Capabilities: Exploits; T1588.005 Obtain Capabilities: Exploits

Execution

T1658 Exploitation for Client Execution

Initial Access

T1664 Exploitation for Initial Access

Affected products and versions in Pwn2Own Ireland 2026

  • Google — Pixel 10
    Vulnerable versions: Unspecified - builds at time of competition (October 2026)

Remediation for Pwn2Own Ireland 2026

Patches

  • No patches or CVEs published as of 2026-10-09; apply Pixel security updates as released

Immediate actions

  • Keep Pixel 10 devices on the latest Android and Google Pixel security update
  • Monitor Google Pixel / Android Security Bulletins for fixes attributed to Pwn2Own Ireland 2026 submissions

Workarounds

  • No workaround published; limit exposure of high-risk users to untrusted remote content until fixes ship

Longer-term hardening

  • Enforce mobile device management with OS patch-level compliance for Pixel fleets
  • Track ZDI advisories for CVE assignment once the 90-day vendor window closes

Timeline of Pwn2Own Ireland 2026

  • Day one totals 32 unique zero-days and $388,500 in payouts; Samsung Galaxy S26 is compromised twice, including by Ikotas Labs.
  • White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) attempt the Pixel 10 but cannot get their exploit working within the allotted time.
  • Pwn2Own Ireland 2026 begins in Cork, Ireland, organized by Trend Micro's Zero Day Initiative; Google Pixel 10 is among the targets.
  • Day two schedules further attempts against the Pixel 10 and Galaxy S26, plus printers, smart-home devices and AI infrastructure.
  • No CVEs or technical details published; under Pwn2Own rules Google has 90 days to release fixes before ZDI discloses the flaws.
  • SecurityWeek reports three successful Pixel 10 exploits: Ikotas Labs ($300,000), Tim Becker and Yves Bieri ($150,000), Dimitrios Valsamaras and Ken Gannon ($112,500), for a stated total of $560,000.

Sources cited for Pwn2Own Ireland 2026

Detection coverage for TL-2026-3103

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3103 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
9 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats