Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools.

Hackers

Pwn2Own Ireland 2026 has come to an end, and participants earned more than $1.2 million for exploits targeting phones, printers, smart speakers, smart home hubs, a wellness device, AI infrastructure and coding tools, and cloud databases.

The highest rewards were paid out for Google Pixel 10 exploits, which were demonstrated by three teams. They collectively earned more than $560,000 for their work.

The Ikotas Labs team earned the full $300,000 payout by chaining multiple bugs to remotely hack a Pixel phone.

Tim Becker and Yves Bieri received $150,000 for their Pixel exploit — they did not get the full payout because their exploit involved a previously known flaw.

The third Pixel hack was demonstrated by Dimitrios Valsamaras and Ken Gannon, who earned $112,500 for an exploit that chained a zero-day with a previously known vulnerability. 

Last year, Valsamaras and Gannon earned $50,000 for hacking a Samsung Galaxy S25 device. They later showed how they exploited vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices.

Advertisement. Scroll to continue reading.

In addition to the Pixel exploits, a significant reward, $50,000, was earned by a researcher for a Sonos Era 300 smart speaker hack.

Rewards of $40,000 were paid out for several exploits, including ones targeting Oracle Autonomous AI Database, OpenAI Codex, Nvidia’s Dynamo AI inference framework, the LiteLLM AI gateway, and the Philips Hue Bridge Pro smart lighting hub.

Researchers received roughly $30,000 for exploits targeting the Samsung Galaxy S26 and the Home Assistant Green smart home hub. 

Pwn2Own participants earned $20,000 for hacking Lexmark and Brother printers, and the Garmin Index BPM blood pressure monitor.

Rewards ranging from $4,250 to $17,500 were paid out for exploits involving Sonos Era, Galaxy S26, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, Home Assistant Green, Chroma, Garmin Index BPM, and Canon imageFORCE 1643F. 

Affected vendors will be provided with the full details of all exploits.

No one targeted the iPhone 17 and WhatsApp, both of which had a maximum prize of $300,000. 

Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Related: Android’s October 2026 Updates Patch 25 Vulnerabilities

Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.