
Three Remote Exploits Breach Fully Patched Pixel 10 at Pwn2Own Ireland for $562,500
Pwn2Own Ireland produced three remote Pixel 10 compromises worth over half a million dollars, all on the latest patch level. Evidence shows repeated use of known but unpatched issues, contradicting vendor claims of rapid remediation. The results highlight persistent gaps in baseband and browser isolation that will affect user devices until at least the 90-day disclosure deadline.
At Pwn2Own Ireland, Xint, Ikotas Labs, and a team led by Dimitrios Valsamaras each demonstrated remote entry into Pixel 10 units running the October 6 security patch level. Entries were registered under remote attack surface rules covering the default browser or radio interfaces. Ikotas Labs received the $300,000 top award despite its entry also being logged as a collision, while Xint's single-bug collision was halved to $150,000. All three succeeded where one other attempt timed out.
ZDI: Google will assign CVEs and ship patches for the three Pixel 10 chains in the December 2026 bulletin or technical details will be published by January 2027.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/10/three-teams-demonstrate-remote-hacks-of.html)
- [2]Supporting Source(https://www.zerodayinitiative.com/blog/2026/10/pwn2own-ireland-2026-results)