Threat reportVulnerabilityTL-2026-3103
Pwn2Own Ireland 2026: Google Pixel 10 Exploit Chains Earn $560,000
Pwn2Own Ireland 2026 (TL-2026-3103), also tracked as Pwn2Own Ireland 2026 Pixel 10, is a medium-severity software vulnerability, first published 2026-10-09. It has no confirmed attribution, affects Google Pixel 10, maps to 5 MITRE ATT&CK techniques (T1404, T1587.004, T1588.005), and is covered by 9 detection rules and 9 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-3103
- Threat ID
- TL-2026-3103
- Also known as
- Pwn2Own Ireland 2026 Pixel 10
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- consumer, enterprise-mobility
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
How Pwn2Own Ireland 2026 works
Three teams demonstrated exploits against the Google Pixel 10 at Pwn2Own Ireland 2026 (Cork, organized by Trend Micro's Zero Day Initiative), earning $560,000 in total. Ikotas Labs received a full $300,000 payout for chaining multiple bugs for remote compromise; two other teams received reduced payouts for exploits that involved a previously known vulnerability. No CVEs, patches or technical details have been published.
Pwn2Own Ireland 2026, organized by Trend Micro's Zero Day Initiative (ZDI), began on October 6, 2026 in Cork, Ireland. According to SecurityWeek (2026-10-09), three teams successfully demonstrated exploits against the Google Pixel 10, collectively earning $560,000. Ikotas Labs received the full $300,000 payout for chaining multiple bugs to achieve a remote device compromise. Tim Becker and Yves Bieri earned $150,000 for an exploit that involved a previously known flaw (a reduced payout), and Dimitrios Valsamaras and Ken Gannon earned $112,500 for chaining a zero-day with a known vulnerability. The per-team amounts listed ($300,000 + $150,000 + $112,500 = $562,500) do not sum to the $560,000 total stated by the source; the stated total is retained here.
No CVE identifiers, CVSS scores, affected Android/Pixel build numbers, vulnerable components or exploit mechanics have been disclosed. Under Pwn2Own rules, vendors receive 90 days to release security updates before ZDI publicly discloses the flaws, so technical details are expected only after a patch or the disclosure deadline. Separate day-one coverage (BleepingComputer) reports that White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) also targeted the Pixel 10 but could not get their exploit to work within the allotted time. Secondary reporting indicates Ikotas Labs also compromised the Samsung Galaxy S26 with a four-vulnerability chain of which one bug was already known to Samsung, and speculates that a previously unknown flaw may also affect the Pixel 10; this is unconfirmed and no details are published.
This is competition-demonstrated research, not in-the-wild exploitation: no CISA KEV listing, public PoC, or threat-actor activity is reported. The entry is tracked in MONITORING status so that downstream phases can add CVEs, patch information and detection content when Google or ZDI publish details. The wider event reportedly totaled about $1.2 million across phones, printers, smart speakers, smart-home hubs, and AI infrastructure targets (Oracle Autonomous AI Database, OpenAI Codex, Nvidia Dynamo, LiteLLM, Philips Hue Bridge Pro, Samsung Galaxy S26, Sonos Era 300).
MITRE ATT&CK techniques used in TL-2026-3103
Privilege Escalation
T1404 Exploitation for Privilege Escalation
Resource Development
T1587.004 Develop Capabilities: Exploits; T1588.005 Obtain Capabilities: Exploits
Execution
T1658 Exploitation for Client Execution
Initial Access
Affected products and versions in Pwn2Own Ireland 2026
- Google — Pixel 10
Vulnerable versions: Unspecified - builds at time of competition (October 2026)
Remediation for Pwn2Own Ireland 2026
Patches
- No patches or CVEs published as of 2026-10-09; apply Pixel security updates as released
Immediate actions
- Keep Pixel 10 devices on the latest Android and Google Pixel security update
- Monitor Google Pixel / Android Security Bulletins for fixes attributed to Pwn2Own Ireland 2026 submissions
Workarounds
- No workaround published; limit exposure of high-risk users to untrusted remote content until fixes ship
Longer-term hardening
- Enforce mobile device management with OS patch-level compliance for Pixel fleets
- Track ZDI advisories for CVE assignment once the 90-day vendor window closes
Timeline of Pwn2Own Ireland 2026
- Day one totals 32 unique zero-days and $388,500 in payouts; Samsung Galaxy S26 is compromised twice, including by Ikotas Labs.
- White Noise Club (Mikhail Evdokimov, Polina Smirnova, Mate Zombor) attempt the Pixel 10 but cannot get their exploit working within the allotted time.
- Pwn2Own Ireland 2026 begins in Cork, Ireland, organized by Trend Micro's Zero Day Initiative; Google Pixel 10 is among the targets.
- Day two schedules further attempts against the Pixel 10 and Galaxy S26, plus printers, smart-home devices and AI infrastructure.
- No CVEs or technical details published; under Pwn2Own rules Google has 90 days to release fixes before ZDI discloses the flaws.
- SecurityWeek reports three successful Pixel 10 exploits: Ikotas Labs ($300,000), Tim Becker and Yves Bieri ($150,000), Dimitrios Valsamaras and Ken Gannon ($112,500), for a stated total of $560,000.
Sources cited for Pwn2Own Ireland 2026
- Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own
- Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
- Hackers crack Samsung Galaxy S26 with single email in zero-day attack
- Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
- Pwn2Own Ireland 2026 - zero days (SecNews)
- Pwn2Own Ireland 2026 Samsung Galaxy S26 hacked three times on day one (IT-Connect)
- Zero Day Initiative blog - Pwn2Own
Detection coverage for TL-2026-3103
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3103 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.